VYPR
Medium severity4.3NVD Advisory· Published Oct 11, 2026

CVE-2026-108574

CVE-2026-108574

Description

A flaw has been found in BerriAI LiteLLM up to 1.95.0. Affected by this issue is the function ui_view_session_spend_logs of the file litellm/proxy/spend_tracking/spend_management_endpoints.py of the component Spend Tracking. Executing a manipulation of the argument session_id can lead to authorization bypass. It is possible to launch the attack remotely. The exploit has been published and may be used. Upgrading to version 1.96.0 can resolve this issue. This patch is called 722d9ffa4f6c5ae15702ab9ab2c5f6bf1688308b. The affected component should be upgraded.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • Berriai/Litellmreferences2 versions
    (expand)+ 1 more
    • (no CPE)
    • (no CPE)range: <=1.95.0

Patches

Vulnerability mechanics

References

6

News mentions

0

No linked articles in our index yet.