LiteLLMGHSA-m2v5-74w2-qhcj
BerriAI litellm: UI User Enumeration leads to System-Wide Information Disclosure
Low4.3CVE-2026-12799 · Published Jun 21, 2026 · updated Sep 14, 2026
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| litellm PyPI | <= 1.82.2 | No fix yet |
Details and references
A security vulnerability has been detected in BerriAI litellm up to 1.82.2. Affected by this issue is the function ui_view_users of the file litellm/proxy/management_endpoints/internal_user_endpoints.py of the component Incomplete Fix CVE-2025-0628. Such manipulation leads to improper authorization. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-266
- Also known as
- CVE-2026-12799
More LiteLLM advisories
All LiteLLM| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jun 21 | LiteLLM: Admin Key Handler Has Improper Authorization CVE-2026-12770Low5.4no fix yet | Low5.4 | No fix yet |
| Jun 21 | LiteLLM: PROXY_ADMIN database API Key Generator Has Insufficient Session Expiration CVE-2026-12772Low6.3no fix yet | Low6.3 | No fix yet |
| Jun 21 | LiteLLM: M2M JWT Handler Has Improper Authorization CVE-2026-12771Low5.0no fix yet | Low5.0 | No fix yet |
| Jun 21 | LiteLLM: MCP Proxy Has Improper Authentication CVE-2026-12773Medium7.3fixed in 1.84.0 | Medium7.3 | 1.84.0 |
| Jun 21 | LiteLLM: SSO Debug Flow Has Improper Authentication CVE-2026-12795Medium7.3no fix yet | Medium7.3 | No fix yet |
| Jun 21 | BerriAI litellm has SSRF via Unvalidated spec_path URL in MCP OpenAPI Spec Loader CVE-2026-12798Low6.3no fix yet | Low6.3 | No fix yet |