Skip to content
COOEY

FAIL › dossier

BerriAI

VENDOR

· dossier confidence 50%

BerriAI's LiteLLM library suffered two high-severity vulnerabilities in 2026, including remote code execution and SQL injection, exposing its core API routing logic to severe compromise risks.

PROFILE
CategoryAI/ML InfrastructureWhat they doBerriAI provides LiteLLM, an open-source library for managing and routing LLM API calls.
SECURITY POSTURE

The company's core product contains critical high-severity vulnerabilities including remote code execution and SQL injection, indicating a lack of robust input validation and secure coding practices in its primary offering.

Notable failures
  • CVE-2026-42271: Authenticated RCE via command injection
  • CVE-2026-42208: SQL injection enabling unauthorized database access
Patterns: critical unpatched vulnerabilities in core product; lack of input validation in API routing logic
FAILURE HISTORY · 2
DATEEVENTSEVSUMMARY
2026-06-08 CVE-2026-42271 high BerriAI LiteLLM allows authenticated users to execute arbitrary host commands via command injection.
2026-05-08 CVE-2026-42208 high BerriAI LiteLLM contains a SQL injection vulnerability enabling unauthorized database access and credential theft.
Open questions: What is the exact founding date of BerriAI? · What is the precise headquarters location of BerriAI? · What is the current employee count of BerriAI?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-28 04:02:29.904088+00:00