CVE-2026-40217: LiteLLM

High severity, CVSS 8.8. EPSS: 3.4% chance of exploitation in the next 30 days.

LiteLLM through 2026-04-08 allows remote attackers to execute arbitrary code via bytecode rewriting at the /guardrails/test_custom_code URI.

Affected products

  • LiteLLM LiteLLM: up to and including 2026-04-08

Published 2026-04-10. Last modified 2026-07-15.