Skip to content

BerriAI security advisories

42 advisories across LiteLLM

Company profile
DateAdvisory
Sep 17LiteLLM Proxy has server-side request forgery via the `user_config` request parameter
CVE-2026-59823Mediumfixed in 1.83.9
Aug 27LiteLLM vulnerable to server-side template injection in the /prompts/test endpoint
CVE-2026-37004Critical9.8fixed in 1.83.7
Jul 22LiteLLM: Custom Code Guardrails production endpoints bypass code safety checks
CVE-2026-59821Lowfixed in 1.82.0
Jul 22LiteLLM: MCP Authentication Bypass via OAuth2 Passthrough Fallback
CVE-2026-59822Highfixed in 1.84.0
Jul 22LiteLLM: Local file read via request-supplied OIDC file references
CVE-2026-59819Lowfixed in 1.83.10
Jul 22LiteLLM: Arbitrary file write via path traversal in Skills archive extraction
CVE-2026-59820Mediumfixed in 1.83.7
Jun 21BerriAI litellm has SSRF via Unvalidated spec_path URL in MCP OpenAPI Spec Loader
CVE-2026-12798Low6.3no fix yet
Jun 21BerriAI litellm: UI User Enumeration leads to System-Wide Information Disclosure
CVE-2026-12799Low4.3no fix yet
Jun 21BerriAI litellm has Security Feature Bypass in BannedKeywords and AzureContentSafety Guardrails via call_type Mismatch on Async Endpoints
CVE-2026-12797Low6.3no fix yet
Jun 21BerriAI litellm: SSO Login Does Not Invalidate Previous UI Session Tokens
CVE-2026-12796Low6.3no fix yet
Jun 21LiteLLM: SSO Debug Flow Has Improper Authentication
CVE-2026-12795Medium7.3no fix yet
Jun 21LiteLLM: MCP Proxy Has Improper Authentication
CVE-2026-12773Medium7.3fixed in 1.84.0
Jun 21LiteLLM: Admin Key Handler Has Improper Authorization
CVE-2026-12770Low5.4no fix yet
Jun 21LiteLLM: PROXY_ADMIN database API Key Generator Has Insufficient Session Expiration
CVE-2026-12772Low6.3no fix yet
Jun 21LiteLLM: M2M JWT Handler Has Improper Authorization
CVE-2026-12771Low5.0no fix yet
Jun 16LiteLLM: Authentication Bypass via Host Header Injection
CVE-2026-49468Critical9.8fixed in 1.84.0
May 21LiteLLM allows a user to modify their own user_role via the /user/update endpoint
CVE-2026-47102High8.8fixed in 1.83.10
May 21LiteLLM allows an authenticated internal_user to create API keys with access to routes that their role does not permit
CVE-2026-47101High8.8fixed in 1.83.14
May 11LiteLLM has a sandbox escape in custom-code guardrail
CVE-2026-40217High8.8fixed in 1.83.10
Apr 25LiteLLM: Authenticated command execution via MCP stdio test endpoints
CVE-2026-42271High8.8fixed in 1.83.7
Apr 24LiteLLM has SQL Injection in Proxy API key verification
CVE-2026-42208Critical9.8fixed in 1.83.7
Apr 24LiteLLM: Server-Side Template Injection in /prompts/test endpoint
CVE-2026-42203Highfixed in 1.83.7
Apr 8LiteLLM: Password hash exposure and pass-the-hash authentication bypass
GHSA-69x8-hrgq-fjj8Highfixed in 1.83.0
Apr 3LiteLLM: Authentication bypass via OIDC userinfo cache key collision
CVE-2026-35030Criticalfixed in 1.83.0
Apr 3LiteLLM: Privilege escalation via unrestricted proxy configuration endpoint
CVE-2026-35029Highfixed in 1.83.0
Mar 25Two LiteLLM versions published containing credential harvesting malware
GHSA-5mg7-485q-xm76Criticalno fix yet
Mar 24Two litellm versions published containing credential harvesting malware
PYSEC-2026-2Unratedno fix yet
Mar 24Malicious code in litellm (PyPI)
MAL-2026-2144Unratedno fix yet
Mar 202025LiteLLM Has a Leakage of Langfuse API Keys
CVE-2025-0330High7.5no fix yet
Mar 202025LiteLLM Has an Improper Authorization Vulnerability
CVE-2025-0628High8.1fixed in 1.61.15
Mar 202025LiteLLM Reveals Portion of API Key via a Logging File
CVE-2024-9606High7.5fixed in 1.44.12
Mar 202025LiteLLM Vulnerable to Denial of Service (DoS) via Crafted HTTP Request
CVE-2024-8984High7.5fixed in 1.56.2
Mar 202025LiteLLM Vulnerable to Remote Code Execution (RCE)
CVE-2024-6825High8.8no fix yet
Mar 202025LiteLLM Vulnerable to Denial of Service (DoS)
CVE-2024-10188High7.5fixed in 1.53.1.dev1
Sep 132024LiteLLM Server-Side Request Forgery (SSRF) vulnerability
CVE-2024-6587High7.5fixed in 1.44.8
Jun 272024litellm vulnerable to remote code execution based on using eval unsafely
CVE-2024-5751Critical9.8fixed in 1.40.16
Jun 272024litellm vulnerable to improper access control in team management
CVE-2024-5710Medium5.3fixed in 1.40.15
Jun 62024Arbitrary file deletion in litellm
CVE-2024-4888High6.5fixed in 1.35.36
Jun 62024SQL injection in litellm
CVE-2024-4890Medium4.9no fix yet
Jun 62024SQL injection in litellm
CVE-2024-5225Medium6.4fixed in 1.40.0
May 182024litellm passes untrusted data to `eval` function without sanitization
CVE-2024-4264High7.2no fix yet
Apr 102024LiteLLM has Server-Side Template Injection vulnerability in /completions endpoint
CVE-2024-2952Critical9.8fixed in 1.34.42

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.