Litellm
by Pypi
Source repositories
CVEs (6)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-30623 | cri | 0.64 | 9.8 | 0.06 | Jul 15, 2026 | litellm: LiteLLM: Remote code execution via unvalidated MCP server configuration | ||
| CVE-2026-59820 | imp | 0.46 | 8.1 | 0.00 | Jul 8, 2026 | litellm: LiteLLM: Directory traversal via crafted skill archive upload | ||
| CVE-2026-59819 | mod | 0.25 | 4.9 | 0.00 | Jul 8, 2026 | litellm: LiteLLM: Information disclosure via local file read in test connection endpoint | ||
| CVE-2026-12799 | 0.00 | — | 0.00 | Jun 21, 2026 | A security vulnerability has been detected in BerriAI litellm up to 1.82.2. Affected by this issue is the function ui_view_users of the file litellm/proxy/management_endpoints/internal_user_endpoints.py of the component Incomplete Fix CVE-2025-0628. Such manipulation leads to… | |||
| CVE-2026-12798 | 0.00 | — | 0.00 | Jun 21, 2026 | A weakness has been identified in BerriAI litellm up to 1.82.2. Affected by this vulnerability is the function load_openapi_spec_async of the file litellm/proxy/_experimental/mcp_server/openapi_to_mcp_generator.py of the component MCP OpenAPI Spec Loader. This manipulation of… | |||
| CVE-2026-12795 | 0.00 | — | 0.01 | Jun 21, 2026 | A vulnerability was determined in BerriAI litellm up to 1.82.2. This affects the function json.dumps of the file litellm/proxy/management_endpoints/ui_sso.py of the component SSO Debug Flow. Executing a manipulation can lead to missing authentication. The attack can be executed… |
- risk 0.64cvss 9.8epss 0.06
litellm: LiteLLM: Remote code execution via unvalidated MCP server configuration
- risk 0.46cvss 8.1epss 0.00
litellm: LiteLLM: Directory traversal via crafted skill archive upload
- risk 0.25cvss 4.9epss 0.00
litellm: LiteLLM: Information disclosure via local file read in test connection endpoint
- CVE-2026-12799Jun 21, 2026risk 0.00cvss —epss 0.00
A security vulnerability has been detected in BerriAI litellm up to 1.82.2. Affected by this issue is the function ui_view_users of the file litellm/proxy/management_endpoints/internal_user_endpoints.py of the component Incomplete Fix CVE-2025-0628. Such manipulation leads to…
- CVE-2026-12798Jun 21, 2026risk 0.00cvss —epss 0.00
A weakness has been identified in BerriAI litellm up to 1.82.2. Affected by this vulnerability is the function load_openapi_spec_async of the file litellm/proxy/_experimental/mcp_server/openapi_to_mcp_generator.py of the component MCP OpenAPI Spec Loader. This manipulation of…
- CVE-2026-12795Jun 21, 2026risk 0.00cvss —epss 0.01
A vulnerability was determined in BerriAI litellm up to 1.82.2. This affects the function json.dumps of the file litellm/proxy/management_endpoints/ui_sso.py of the component SSO Debug Flow. Executing a manipulation can lead to missing authentication. The attack can be executed…