{"data":{"id":"2d208365-42c7-4d1f-9524-83bc2c48eac0","title":"CVE-2026-89032: BerriAI LiteLLM before 1.101.0-rc.1 contains a tenant isolation bypass vulnerability in the semantic cache layer that al","summary":"BerriAI LiteLLM before version 1.101.0-rc.1 has a tenant isolation bypass vulnerability in its semantic cache layer (a system that stores and reuses AI responses based on meaning rather than exact text matching). Authenticated attackers with a valid virtual key can exploit a mismatch in how the system tracks which tenant owns cached data, allowing them to read other tenants' sensitive information like personal data or source code, and potentially trick AI systems into running malicious commands under someone else's account.","solution":"Update to BerriAI LiteLLM version 1.101.0-rc.1 or later.","labels":["security"],"sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-89032","publishedAt":"2026-09-25T17:17:18.793Z","cveId":"CVE-2026-89032","cweIds":["CWE-863"],"cvssScore":"7.7","cvssSeverity":"high","severity":"high","attackType":["data_extraction"],"issueType":"vulnerability","affectedPackages":null,"affectedVendors":["LangChain"],"affectedVendorsRaw":["BerriAI LiteLLM"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N","attackVector":"network","attackComplexity":"high","privilegesRequired":"low","userInteraction":"required","exploitMaturity":"unknown","epssScore":0,"patchAvailable":null,"disclosureDate":"2026-09-25T17:17:18.793Z","capecIds":["CAPEC-122"],"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality","integrity"],"aiComponentTargeted":"api","llmSpecific":true,"classifierConfidence":0.92,"researchCategory":null,"atlasIds":null}}