Skip to content
LiteLLMGHSA-4jcj-7x88-m979

LiteLLM: MCP Proxy Has Improper Authentication

Medium7.3CVE-2026-12773 · Published Jun 21, 2026 · updated Sep 10, 2026

A weakness has been identified in BerriAI litellm up to 1.59.8. Affected is the function UserAPIKeyAuth of the file litellm/proxy/_experimental/mcp_server/auth/user_api_key_auth_mcp.py of the component MCP Proxy. Executing a manipulation can lead to improper authentication. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure.

GitHub advisory

Affected versions

PackageAffectedFixed in
litellm
PyPI
< 1.84.01.84.0
Details and references

More LiteLLM advisories

All LiteLLM
Advisory
BerriAI litellm has SSRF via Unvalidated spec_path URL in MCP OpenAPI Spec Loader
Low6.3Jun 21
BerriAI litellm: UI User Enumeration leads to System-Wide Information Disclosure
Low4.3Jun 21
LiteLLM: improper authorization
Low6.3Jun 21
BerriAI litellm: SSO Login Does Not Invalidate Previous UI Session Tokens
Low6.3Jun 21
LiteLLM: SSO Debug Flow Has Improper Authentication
Medium7.3Jun 21
LiteLLM: Admin Key Handler Has Improper Authorization
Low5.4Jun 21

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.