{"data":{"id":"2c95e681-7145-43c6-ad35-053819943d13","title":"GHSA-j37q-q7p9-vpwm: LiteLLM: SSO Debug Flow Has Improper Authentication","summary":"A vulnerability in BerriAI litellm up to version 1.82.2 affects the json.dumps function in litellm/proxy/management_endpoints/ui_sso.py, part of the SSO Debug Flow component. Manipulating this component can lead to missing authentication, and the attack can be executed remotely. The exploit has been publicly disclosed and may be used, and the vendor was contacted early about the disclosure.","solution":"N/A -- no mitigation discussed in source.","labels":["security"],"sourceUrl":"https://github.com/advisories/GHSA-j37q-q7p9-vpwm","publishedAt":"2026-06-21T09:30:51.000Z","cveId":"CVE-2026-12795","cweIds":["CWE-287"],"cvssScore":"7.3","cvssSeverity":"medium","severity":"medium","attackType":["other"],"issueType":"vulnerability","affectedPackages":["litellm@<= 1.82.2"],"affectedPackageNames":["litellm"],"affectedPackageRefs":["pypi:litellm"],"affectedVendors":["LangChain"],"affectedVendorsRaw":["LiteLLM"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","summaryPromptVersion":"v2","headline":null,"headlinePromptVersion":null,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","attackVector":"network","attackComplexity":"low","privilegesRequired":"none","userInteraction":"none","exploitMaturity":"unknown","epssScore":0.00795,"epssCheckedAt":"2026-10-10T04:57:20.082Z","kevDateAdded":null,"advisoryAliases":["GHSA-j37q-q7p9-vpwm"],"affectedPackagesSource":null,"affectedPackagesCheckedAt":null,"patchAvailable":null,"disclosureDate":"2026-06-21T09:30:51.000Z","capecIds":["CAPEC-114"],"crossRefCount":0,"attackSophistication":"trivial","impactType":["confidentiality","integrity"],"aiComponentTargeted":"api","llmSpecific":true,"classifierConfidence":0.9,"researchCategory":null,"atlasIds":null}}