Berriai Litellm vulnerabilities
25 known vulnerabilities affecting berriai/litellm.
Total CVEs
25
CISA KEV
4
actively exploited
Public exploits
4
Exploited in wild
7
Severity breakdown
CRITICAL4HIGH13MEDIUM8
Vulnerabilities
Page 2 of 2
CVE-2026-12774P3MEDIUMCVSS 6.3v1.82.0v1.82.1+1 more2026-06-21
CVE-2026-12774 [MEDIUM] CWE-918 CVE-2026-12774: A security vulnerability has been detected in BerriAI litellm up to 1.82.2. Affected by this vulnera
A security vulnerability has been detected in BerriAI litellm up to 1.82.2. Affected by this vulnerability is the function _execute_with_mcp_client of the file litellm/proxy/_experimental/mcp_server/rest_endpoints.py of the component MCP Server Connection Testing. The manipulation leads to server-side request forgery. Remote exploitation of the atta
nvd
CVE-2026-12798P3MEDIUMCVSS 6.3v1.82.0v1.82.1+1 more2026-06-21
CVE-2026-12798 [MEDIUM] CWE-918 CVE-2026-12798: A weakness has been identified in BerriAI litellm up to 1.82.2. Affected by this vulnerability is th
A weakness has been identified in BerriAI litellm up to 1.82.2. Affected by this vulnerability is the function load_openapi_spec_async of the file litellm/proxy/_experimental/mcp_server/openapi_to_mcp_generator.py of the component MCP OpenAPI Spec Loader. This manipulation of the argument spec_path causes server-side request forgery. It is possible
nvd
CVE-2026-59820P3MEDIUMCVSS 6.5fixed in 1.83.7-stable2026-07-08
CVE-2026-59820 [MEDIUM] CWE-22 CVE-2026-59820: LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.
LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.7-stable, LiteLLM Skills archive extraction did not sufficiently validate file paths from uploaded skill ZIP archives, allowing an authenticated user with access to LiteLLM LLM API routes or a key whose allowed_routes includes /v1/skills, anthropic_rou
nvd
CVE-2026-84377P3MEDIUMCVSS 6.5fixed in 1.88.6v>= 1.89.0, < 1.96.22026-09-02
CVE-2026-84377 [MEDIUM] CWE-918 CVE-2026-84377: LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to versi
LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to versions 1.88.6 and 1.96.2, any authenticated LiteLLM proxy user could redirect an outbound provider call to a destination the user controls and cause the proxy to send its configured provider credentials to that destination. Request validation in litellm/
nvd
CVE-2026-59819P4MEDIUMCVSS 4.9fixed in 1.83.10-stable2026-07-08
CVE-2026-59819 [MEDIUM] CWE-73 CVE-2026-59819: LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.
LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.10-stable, LiteLLM's /health/test_connection endpoint resolved request-supplied environment and OIDC file references in litellm_params, allowing a proxy administrator or another privileged caller with permission to test model connections to read files
nvd
← Previous2 / 2