Skip to content
LiteLLMGHSA-qmf3-4767-5fg3

LiteLLM: M2M JWT Handler Has Improper Authorization

Low5.0CVE-2026-12771 · Published Jun 21, 2026 · updated Sep 10, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
litellm
PyPI
<= 1.82.2No fix yet
Details and references

A vulnerability was identified in BerriAI litellm up to 1.82.2. This affects an unknown function of the file litellm/proxy/auth/user_api_key_auth.py of the component M2M JWT Handler. Such manipulation leads to improper authorization. The attack can be launched remotely. A high complexity level is associated with this attack. The exploitability is reported as difficult. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure.

CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L
Severity from
GitHub (reviewed advisory)
Weakness
CWE-266, CWE-285
Also known as
CVE-2026-12771

More LiteLLM advisories

All LiteLLM
DateAdvisory
Jun 21LiteLLM: Admin Key Handler Has Improper Authorization
CVE-2026-12770Low5.4no fix yet
Jun 21LiteLLM: PROXY_ADMIN database API Key Generator Has Insufficient Session Expiration
CVE-2026-12772Low6.3no fix yet
Jun 21LiteLLM: MCP Proxy Has Improper Authentication
CVE-2026-12773Medium7.3fixed in 1.84.0
Jun 21LiteLLM: SSO Debug Flow Has Improper Authentication
CVE-2026-12795Medium7.3no fix yet
Jun 21BerriAI litellm has SSRF via Unvalidated spec_path URL in MCP OpenAPI Spec Loader
CVE-2026-12798Low6.3no fix yet
Jun 21BerriAI litellm: UI User Enumeration leads to System-Wide Information Disclosure
CVE-2026-12799Low4.3no fix yet

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.