Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-40217

Опубликовано: 10 апр. 2026
Источник: redhat
CVSS3: 8.8
EPSS Низкий

Описание

LiteLLM through 2026-04-08 allows remote attackers to execute arbitrary code via bytecode rewriting at the /guardrails/test_custom_code URI.

A flaw was found in LiteLLM. A remote attacker can exploit this flaw by performing bytecode rewriting at the /guardrails/test_custom_code URI. This could lead to arbitrary code execution, allowing the attacker to run malicious code on the affected system.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Lightspeed Coreredhat-user-workloads/lightspeed-stackAffected
Red Hat OpenShift AI (RHOAI)rhoai/odh-mlflow-rhel9Not affected
Red Hat Ansible Automation Platform 2.6ansible-automation-platform-26/lightspeed-chatbot-rhel9FixedRHSA-2026:2486609.06.2026
Red Hat OpenShift AI 3.3rhoai/odh-llama-stack-core-rhel9FixedRHSA-2026:3005625.06.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-94
https://bugzilla.redhat.com/show_bug.cgi?id=2457301LiteLLM: LiteLLM: Arbitrary Code Execution via bytecode rewriting

EPSS

Процентиль: 93%
0.06496
Низкий

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
nvd
4 месяца назад

LiteLLM through 2026-04-08 allows remote attackers to execute arbitrary code via bytecode rewriting at the /guardrails/test_custom_code URI.

CVSS3: 8.8
github
3 месяца назад

LiteLLM has a sandbox escape in custom-code guardrail

CVSS3: 8.8
fstec
6 месяцев назад

Уязвимость прокси-сервера LiteLLM, связанная с использованием незащищенного альтернативного канала, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 93%
0.06496
Низкий

8.8 High

CVSS3