Skip to content
LiteLLMGHSA-m2v5-74w2-qhcj

BerriAI litellm: UI User Enumeration leads to System-Wide Information Disclosure

Low4.3CVE-2026-12799 · Published Jun 21, 2026 · updated Sep 14, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
litellm
PyPI
<= 1.82.2No fix yet
Details and references

A security vulnerability has been detected in BerriAI litellm up to 1.82.2. Affected by this issue is the function ui_view_users of the file litellm/proxy/management_endpoints/internal_user_endpoints.py of the component Incomplete Fix CVE-2025-0628. Such manipulation leads to improper authorization. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-266
Also known as
CVE-2026-12799

More LiteLLM advisories

All LiteLLM
DateAdvisory
Jun 21LiteLLM: Admin Key Handler Has Improper Authorization
CVE-2026-12770Low5.4no fix yet
Jun 21LiteLLM: PROXY_ADMIN database API Key Generator Has Insufficient Session Expiration
CVE-2026-12772Low6.3no fix yet
Jun 21LiteLLM: M2M JWT Handler Has Improper Authorization
CVE-2026-12771Low5.0no fix yet
Jun 21LiteLLM: MCP Proxy Has Improper Authentication
CVE-2026-12773Medium7.3fixed in 1.84.0
Jun 21LiteLLM: SSO Debug Flow Has Improper Authentication
CVE-2026-12795Medium7.3no fix yet
Jun 21BerriAI litellm has SSRF via Unvalidated spec_path URL in MCP OpenAPI Spec Loader
CVE-2026-12798Low6.3no fix yet

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.