LiteLLMGHSA-p897-vf7j-f5h8
BerriAI litellm has Security Feature Bypass in BannedKeywords and AzureContentSafety Guardrails via call_type Mismatch on Async Endpoints
Low6.3CVE-2026-12797 · Published Jun 21, 2026 · updated Sep 14, 2026
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| litellm PyPI | <= 1.82.5 | No fix yet |
Details and references
A security flaw has been discovered in BerriAI litellm up to 1.82.5. Affected is the function async_pre_call_hook of the file enterprise/enterprise_hooks/banned_keywords.py of the component Completions Interface. The manipulation of the argument prompt results in incorrect authorization. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-285
- Also known as
- CVE-2026-12797
More LiteLLM advisories
All LiteLLM| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jun 21 | LiteLLM: Admin Key Handler Has Improper Authorization CVE-2026-12770Low5.4no fix yet | Low5.4 | No fix yet |
| Jun 21 | LiteLLM: PROXY_ADMIN database API Key Generator Has Insufficient Session Expiration CVE-2026-12772Low6.3no fix yet | Low6.3 | No fix yet |
| Jun 21 | LiteLLM: M2M JWT Handler Has Improper Authorization CVE-2026-12771Low5.0no fix yet | Low5.0 | No fix yet |
| Jun 21 | LiteLLM: MCP Proxy Has Improper Authentication CVE-2026-12773Medium7.3fixed in 1.84.0 | Medium7.3 | 1.84.0 |
| Jun 21 | LiteLLM: SSO Debug Flow Has Improper Authentication CVE-2026-12795Medium7.3no fix yet | Medium7.3 | No fix yet |
| Jun 21 | BerriAI litellm has SSRF via Unvalidated spec_path URL in MCP OpenAPI Spec Loader CVE-2026-12798Low6.3no fix yet | Low6.3 | No fix yet |