Skip to content
LiteLLMGHSA-fjcf-3j3r-78rp

LiteLLM Has an Improper Authorization Vulnerability

High8.1CVE-2025-0628 · Published Mar 20, 2025 · updated Sep 10, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
litellm
PyPI
< 1.61.151.61.15
Details and references

An improper authorization vulnerability exists in the main-latest version of BerriAI/litellm. When a user with the role 'internal_user_viewer' logs into the application, they are provided with an overly privileged API key. This key can be used to access all the admin functionality of the application, including endpoints such as '/users/list' and '/users/get_users'. This vulnerability allows for privilege escalation within the application, enabling any account to become a PROXY ADMIN.

CVSS 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-266, CWE-285
Also known as
CVE-2025-0628, PYSEC-2026-1546

More LiteLLM advisories

All LiteLLM
DateAdvisory
Mar 202025LiteLLM Vulnerable to Denial of Service (DoS)
CVE-2024-10188High7.5fixed in 1.53.1.dev1
Mar 202025LiteLLM Vulnerable to Remote Code Execution (RCE)
CVE-2024-6825High8.8no fix yet
Mar 202025LiteLLM Vulnerable to Denial of Service (DoS) via Crafted HTTP Request
CVE-2024-8984High7.5fixed in 1.56.2
Mar 202025LiteLLM Reveals Portion of API Key via a Logging File
CVE-2024-9606High7.5fixed in 1.44.12
Mar 202025LiteLLM Has a Leakage of Langfuse API Keys
CVE-2025-0330High7.5no fix yet
Sep 132024LiteLLM Server-Side Request Forgery (SSRF) vulnerability
CVE-2024-6587High7.5fixed in 1.44.8

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.