Litellm

Litellm

39 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.51%
  • Veröffentlicht 21.06.2026 08:30:07
  • Zuletzt bearbeitet 24.06.2026 20:15:08

A vulnerability was determined in BerriAI litellm up to 1.82.2. This affects the function json.dumps of the file litellm/proxy/management_endpoints/ui_sso.py of the component SSO Debug Flow. Executing a manipulation can lead to missing authentication...

Exploit
  • EPSS 0.26%
  • Veröffentlicht 21.06.2026 03:45:06
  • Zuletzt bearbeitet 24.06.2026 20:24:17

A security vulnerability has been detected in BerriAI litellm up to 1.82.2. Affected by this vulnerability is the function _execute_with_mcp_client of the file litellm/proxy/_experimental/mcp_server/rest_endpoints.py of the component MCP Server Conne...

Exploit
  • EPSS 0.61%
  • Veröffentlicht 21.06.2026 03:15:08
  • Zuletzt bearbeitet 15.07.2026 02:18:11

A weakness has been identified in BerriAI litellm up to 1.59.8. Affected is the function UserAPIKeyAuth of the file litellm/proxy/_experimental/mcp_server/auth/user_api_key_auth_mcp.py of the component MCP Proxy. Executing a manipulation can lead to ...

Exploit
  • EPSS 0.26%
  • Veröffentlicht 21.06.2026 02:00:08
  • Zuletzt bearbeitet 24.06.2026 20:28:58

A security flaw has been discovered in BerriAI litellm up to 1.82.2. This impacts the function authenticate_user of the file litellm/proxy/auth/login_utils.py of the component PROXY_ADMIN database API Key Generator. Performing a manipulation results ...

Exploit
  • EPSS 0.29%
  • Veröffentlicht 21.06.2026 01:00:12
  • Zuletzt bearbeitet 24.06.2026 20:31:58

A vulnerability was identified in BerriAI litellm up to 1.82.2. This affects an unknown function of the file litellm/proxy/auth/user_api_key_auth.py of the component M2M JWT Handler. Such manipulation leads to improper authorization. The attack can b...

Exploit
  • EPSS 0.34%
  • Veröffentlicht 21.06.2026 00:15:08
  • Zuletzt bearbeitet 24.06.2026 20:37:26

A vulnerability was determined in BerriAI litellm up to 1.63.1. The impacted element is an unknown function of the file litellm/proxy/management_endpoints/key_management_endpoints.py of the component Admin Key Handler. This manipulation causes improp...

Medienbericht Exploit
  • EPSS 0.65%
  • Veröffentlicht 21.05.2026 20:34:37
  • Zuletzt bearbeitet 23.07.2026 16:10:00

LiteLLM prior to 1.83.10 allows a user to modify their own user_role via the /user/update endpoint. While the endpoint correctly restricts users to updating only their own account, it does not restrict which fields may be changed. A user who can reac...

Medienbericht Exploit
  • EPSS 0.74%
  • Veröffentlicht 21.05.2026 20:33:30
  • Zuletzt bearbeitet 23.07.2026 16:10:00

LiteLLM prior to 1.83.14 allows an authenticated internal_user to create API keys with access to routes that their role does not permit. When generating a key, the allowed_routes field is stored without verifying that the specified routes fall within...

Warnung Medienbericht
  • EPSS 89.42%
  • Veröffentlicht 08.05.2026 03:38:14
  • Zuletzt bearbeitet 15.07.2026 02:21:28

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.81.16 to before version 1.83.7, a database query used during proxy API key checks mixed the caller-supplied key value into the query text instead of ...

  • EPSS 0.37%
  • Veröffentlicht 08.05.2026 03:36:58
  • Zuletzt bearbeitet 15.07.2026 02:21:26

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.80.5 to before version 1.83.7, the POST /prompts/test endpoint accepted user-supplied prompt templates and rendered them without sandboxing. A crafte...