<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>WildforTech Security Advisories — BerriAI</title><description>Actively exploited vulnerabilities affecting BerriAI products.</description><link>https://wildfortech.com</link><atom:link href="https://wildfortech.com/security/vendor/berriai.xml" rel="self" type="application/rss+xml"/><item><title>CVE-2026-42271 — BerriAI LiteLLM Command Injection Vulnerability</title><link>https://wildfortech.com/security#CVE-2026-42271</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2026-42271</guid><description>This vulnerability in BerriAI LiteLLM allows any authenticated user — even those with low-privilege internal-user keys — to inject and execute arbitrary commands directly on the underlying host system. This is a critical risk because it means attackers don&apos;t need administrative access to take control of the server. A compromised or malicious low-privilege account could be used to exfiltrate data, pivot to other systems, or fully compromise the host running LiteLLM.</description><pubDate>Mon, 08 Jun 2026 00:00:00 GMT</pubDate><category>BerriAI</category><category>LiteLLM</category></item><item><title>CVE-2026-42208 — BerriAI LiteLLM SQL Injection Vulnerability</title><link>https://wildfortech.com/security#CVE-2026-42208</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2026-42208</guid><description>BerriAI LiteLLM, a popular proxy for managing LLM API calls, contains a SQL injection flaw that lets an attacker read and potentially modify data in the proxy&apos;s underlying database. Because LiteLLM stores credentials for AI services, a successful exploit could expose API keys and access tokens for multiple LLM providers, leading to unauthorized use of those services and potential data exfiltration from any system the proxy touches.</description><pubDate>Fri, 08 May 2026 00:00:00 GMT</pubDate><category>BerriAI</category><category>LiteLLM</category></item></channel></rss>