LiteLLMGHSA-j37q-q7p9-vpwm
LiteLLM: SSO Debug Flow Has Improper Authentication
Medium7.3CVE-2026-12795 · Published Jun 21, 2026 · updated Sep 10, 2026
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| litellm PyPI | <= 1.82.2 | No fix yet |
Details and references
A vulnerability was determined in BerriAI litellm up to 1.82.2. This affects the function json.dumps of the file litellm/proxy/management_endpoints/ui_sso.py of the component SSO Debug Flow. Executing a manipulation can lead to missing authentication. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-287
- Also known as
- CVE-2026-12795
More LiteLLM advisories
All LiteLLM| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jun 21 | LiteLLM: Admin Key Handler Has Improper Authorization CVE-2026-12770Low5.4no fix yet | Low5.4 | No fix yet |
| Jun 21 | LiteLLM: PROXY_ADMIN database API Key Generator Has Insufficient Session Expiration CVE-2026-12772Low6.3no fix yet | Low6.3 | No fix yet |
| Jun 21 | LiteLLM: M2M JWT Handler Has Improper Authorization CVE-2026-12771Low5.0no fix yet | Low5.0 | No fix yet |
| Jun 21 | LiteLLM: MCP Proxy Has Improper Authentication CVE-2026-12773Medium7.3fixed in 1.84.0 | Medium7.3 | 1.84.0 |
| Jun 21 | BerriAI litellm has SSRF via Unvalidated spec_path URL in MCP OpenAPI Spec Loader CVE-2026-12798Low6.3no fix yet | Low6.3 | No fix yet |
| Jun 21 | BerriAI litellm: UI User Enumeration leads to System-Wide Information Disclosure CVE-2026-12799Low4.3no fix yet | Low4.3 | No fix yet |