FAIL › dossier
BerriAI
VENDOR· dossier confidence 50%
BerriAI's LiteLLM library suffered two high-severity vulnerabilities in 2026, including remote code execution and SQL injection, exposing its core API routing logic to severe compromise risks.
PROFILE
CategoryAI/ML InfrastructureWhat they doBerriAI provides LiteLLM, an open-source library for managing and routing LLM API calls.
SECURITY POSTURE
The company's core product contains critical high-severity vulnerabilities including remote code execution and SQL injection, indicating a lack of robust input validation and secure coding practices in its primary offering.
Notable failures
- CVE-2026-42271: Authenticated RCE via command injection
- CVE-2026-42208: SQL injection enabling unauthorized database access
Patterns: critical unpatched vulnerabilities in core product; lack of input validation in API routing logic
FAILURE HISTORY · 2
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2026-06-08 | CVE-2026-42271 | high | BerriAI LiteLLM allows authenticated users to execute arbitrary host commands via command injection. |
| 2026-05-08 | CVE-2026-42208 | high | BerriAI LiteLLM contains a SQL injection vulnerability enabling unauthorized database access and credential theft. |
Open questions: What is the exact founding date of BerriAI? · What is the precise headquarters location of BerriAI? · What is the current employee count of BerriAI?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-28 04:02:29.904088+00:00