SERVER-WEBAPP -- Snort has detected traffic exploiting vulnerabilities in web based applications on servers.
SERVER-WEBAPP BerriAI LiteLLM command injection attempt
This rule looks for traffic to BerriAI LiteLLM testing URIs where the transport method is stdio and the target command is bash.
This rule looks for traffic to BerriAI LiteLLM that contains attempts to execute bash commands on the server host.
Attacks/Scans seen in the wild
Known false positives, with the described conditions
This rule will alert on all attempted bash commands sent to BerriAI LiteLLM servers regardless of whether the originating user / process has the appropriate `PROXY_ADMIN` permissions.
Cisco Talos Intelligence Group
MITRE::ATT&CK Framework::Enterprise::Initial Access::Exploit Public-Facing Application
Vulnerability::Severity::High
Vulnerability::Severity::Critical
Command Injection
Command Injection attacks target applications that allow unsafe user-supplied input. Attackers transmit this input via forms, cookies, HTTP headers, etc. and exploit the applications permissions to execute system commands without injecting code.
CVE-2026-42271 |
Loading description
|