VYPR

Litellm

by Berriai

pypi: litellm

Source repositories

CVEs (42)

  • CVE-2024-4888HigJun 6, 2024
    risk 0.46cvss 8.1epss 0.01

    BerriAI's litellm, in its latest version, is vulnerable to arbitrary file deletion due to improper input validation on the `/audio/transcriptions` endpoint. An attacker can exploit this vulnerability by sending a specially crafted request that includes a file path to the server,…

  • CVE-2024-6587HigSep 13, 2024
    risk 0.45cvss 7.5epss 0.37

    A Server-Side Request Forgery (SSRF) vulnerability exists in berriai/litellm version 1.38.10. This vulnerability allows users to specify the `api_base` parameter when making requests to `POST /chat/completions`, causing the application to send the request to the domain specified…

  • CVE-2024-9606HigMar 20, 2025
    risk 0.42cvss 7.5epss 0.01

    In berriai/litellm before version 1.44.12, the `litellm/litellm_core_utils/litellm_logging.py` file contains a vulnerability where the API key masking code only masks the first 5 characters of the key. This results in the leakage of almost the entire API key in the logs,…

  • CVE-2024-8984HigMar 20, 2025
    risk 0.42cvss 7.5epss 0.01

    A Denial of Service (DoS) vulnerability exists in berriai/litellm version v1.44.5. This vulnerability can be exploited by appending characters, such as dashes (-), to the end of a multipart boundary in an HTTP request. The server continuously processes each character, leading to…

  • CVE-2024-10188HigMar 20, 2025
    risk 0.42cvss 7.5epss 0.01

    A vulnerability in BerriAI/litellm, as of commit 26c03c9, allows unauthenticated users to cause a Denial of Service (DoS) by exploiting the use of ast.literal_eval to parse user input. This function is not safe and is prone to DoS attacks, which can crash the litellm Python…

  • CVE-2026-12798MedJun 21, 2026
    risk 0.41cvss 6.3epss 0.00

    A weakness has been identified in BerriAI litellm up to 1.82.2. Affected by this vulnerability is the function load_openapi_spec_async of the file litellm/proxy/_experimental/mcp_server/openapi_to_mcp_generator.py of the component MCP OpenAPI Spec Loader. This manipulation of…

  • CVE-2026-12797MedJun 21, 2026
    risk 0.41cvss 6.3epss 0.00

    A security flaw has been discovered in BerriAI litellm up to 1.82.5. Affected is the function async_pre_call_hook of the file enterprise/enterprise_hooks/banned_keywords.py of the component Completions Interface. The manipulation of the argument prompt results in incorrect…

  • CVE-2026-12796MedJun 21, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was identified in BerriAI litellm up to 1.82.2. This impacts the function get_redirect_response_from_openid of the file litellm/proxy/management_endpoints/ui_sso.py of the component SSO Authentication Flow. The manipulation leads to session expiration. The attack…

  • CVE-2026-59821HigJul 8, 2026
    risk 0.40cvss 7.2epss 0.00

    LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.82.0-stable, LiteLLM's Custom Code Guardrails production create and update paths did not apply the same sandboxing and validation used by the test endpoint, allowing a privileged…

  • CVE-2026-12773HigJun 21, 2026
    risk 0.40cvss 7.3epss 0.01

    A weakness has been identified in BerriAI litellm up to 1.59.8. Affected is the function UserAPIKeyAuth of the file litellm/proxy/_experimental/mcp_server/auth/user_api_key_auth_mcp.py of the component MCP Proxy. Executing a manipulation can lead to improper authentication. The…

  • CVE-2024-5225HigJun 6, 2024
    risk 0.40cvss 7.2epss 0.00

    An SQL Injection vulnerability exists in the berriai/litellm repository, specifically within the `/global/spend/logs` endpoint. The vulnerability arises due to improper neutralization of special elements used in an SQL command. The affected code constructs an SQL query by…

  • CVE-2026-59820MedJul 8, 2026
    risk 0.35cvss 6.5epss 0.00

    LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.7-stable, LiteLLM Skills archive extraction did not sufficiently validate file paths from uploaded skill ZIP archives, allowing an authenticated user with access to LiteLLM LLM…

  • CVE-2025-45809MedJul 3, 2025
    risk 0.35cvss 5.4epss 0.00

    SQL Injection vulnerability in BerriAI LiteLLM before 1.81.0 allows attackers to execute arbitrary commands via the key parameter to the "/key/block" and "/key/unblock" API endpoints.

  • CVE-2024-5710MedJun 27, 2024
    risk 0.35cvss 6.5epss 0.00

    berriai/litellm version 1.34.34 is vulnerable to improper access control in its team management functionality. This vulnerability allows attackers to perform unauthorized actions such as creating, updating, viewing, deleting, blocking, and unblocking any teams, as well as adding…

  • CVE-2026-12774MedJun 21, 2026
    risk 0.34cvss 6.3epss 0.00

    A security vulnerability has been detected in BerriAI litellm up to 1.82.2. Affected by this vulnerability is the function _execute_with_mcp_client of the file litellm/proxy/_experimental/mcp_server/rest_endpoints.py of the component MCP Server Connection Testing. The…

  • CVE-2026-12772MedJun 21, 2026
    risk 0.34cvss 6.3epss 0.00

    A security flaw has been discovered in BerriAI litellm up to 1.82.2. This impacts the function authenticate_user of the file litellm/proxy/auth/login_utils.py of the component PROXY_ADMIN database API Key Generator. Performing a manipulation results in session expiration. The…

  • CVE-2026-12799MedJun 21, 2026
    risk 0.28cvss 4.3epss 0.00

    A security vulnerability has been detected in BerriAI litellm up to 1.82.2. Affected by this issue is the function ui_view_users of the file litellm/proxy/management_endpoints/internal_user_endpoints.py of the component Incomplete Fix CVE-2025-0628. Such manipulation leads to…

  • CVE-2026-12770MedJun 21, 2026
    risk 0.28cvss 5.4epss 0.00

    A vulnerability was determined in BerriAI litellm up to 1.63.1. The impacted element is an unknown function of the file litellm/proxy/management_endpoints/key_management_endpoints.py of the component Admin Key Handler. This manipulation causes improper authorization. The attack…

  • CVE-2026-12771MedJun 21, 2026
    risk 0.26cvss 5.0epss 0.00

    A vulnerability was identified in BerriAI litellm up to 1.82.2. This affects an unknown function of the file litellm/proxy/auth/user_api_key_auth.py of the component M2M JWT Handler. Such manipulation leads to improper authorization. The attack can be launched remotely. A high…

  • CVE-2026-59819MedJul 8, 2026
    risk 0.25cvss 4.9epss 0.00

    LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.10-stable, LiteLLM's /health/test_connection endpoint resolved request-supplied environment and OIDC file references in litellm_params, allowing a proxy administrator or another…