Skip to content
LiteLLMGHSA-c693-x898-5g4h

BerriAI litellm has SSRF via Unvalidated spec_path URL in MCP OpenAPI Spec Loader

Low6.3CVE-2026-12798 · Published Jun 21, 2026 · updated Sep 14, 2026

A weakness has been identified in BerriAI litellm up to 1.82.2. Affected by this vulnerability is the function load_openapi_spec_async of the file litellm/proxy/_experimental/mcp_server/openapi_to_mcp_generator.py of the component MCP OpenAPI Spec Loader. This manipulation of the argument spec_path causes server-side request forgery. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure.

GitHub advisory

Affected versions

PackageAffectedFixed in
litellm
PyPI
<= 1.82.2No fix yet
Details and references

More LiteLLM advisories

All LiteLLM
Advisory
BerriAI litellm: UI User Enumeration leads to System-Wide Information Disclosure
Low4.3Jun 21
LiteLLM: improper authorization
Low6.3Jun 21
BerriAI litellm: SSO Login Does Not Invalidate Previous UI Session Tokens
Low6.3Jun 21
LiteLLM: SSO Debug Flow Has Improper Authentication
Medium7.3Jun 21
LiteLLM: MCP Proxy Has Improper Authentication
Medium7.3Jun 21
LiteLLM: Admin Key Handler Has Improper Authorization
Low5.4Jun 21

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.