VYPR

Litellm

by Berriai

pypi: litellm

Source repositories

CVEs (45)

  • CVE-2026-12771MedJun 21, 2026
    risk 0.26cvss 5.0epss 0.00

    A vulnerability was identified in BerriAI litellm up to 1.82.2. This affects an unknown function of the file litellm/proxy/auth/user_api_key_auth.py of the component M2M JWT Handler. Such manipulation leads to improper authorization. The attack can be launched remotely. A high…

  • CVE-2026-59819MedJul 8, 2026
    risk 0.25cvss 4.9epss 0.01

    LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.10-stable, LiteLLM's /health/test_connection endpoint resolved request-supplied environment and OIDC file references in litellm_params, allowing a proxy administrator or another…

  • CVE-2024-4890MedJun 6, 2024
    risk 0.25cvss 4.9epss 0.01

    A blind SQL injection vulnerability exists in the berriai/litellm application, specifically within the '/team/update' process. The vulnerability arises due to the improper handling of the 'user_id' parameter in the raw SQL query used for deleting users. An attacker can exploit…

  • CVE-2025-11203LowOct 29, 2025
    risk 0.23cvss 3.5epss 0.00

    LiteLLM Information health API_KEY Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of LiteLLM. Authentication is required to exploit this vulnerability. The specific flaw exists within…

  • CVE-2026-12799MedJun 21, 2026
    risk 0.21cvss 4.3epss 0.00

    A security vulnerability has been detected in BerriAI litellm up to 1.82.2. Affected by this issue is the function ui_view_users of the file litellm/proxy/management_endpoints/internal_user_endpoints.py of the component Incomplete Fix CVE-2025-0628. Such manipulation leads to…

Page 3 of 3