{"data":{"id":"6137cd12-9077-47c6-ae09-65276f19b7cc","title":"GHSA-c693-x898-5g4h: BerriAI litellm has SSRF via Unvalidated spec_path URL in MCP OpenAPI Spec Loader","summary":"A weakness in BerriAI litellm up to 1.82.2 lies in the load_openapi_spec_async function of litellm/proxy/_experimental/mcp_server/openapi_to_mcp_generator.py, within the MCP OpenAPI Spec Loader component. Manipulating the spec_path argument causes server-side request forgery, and it can be exploited remotely. A public exploit exists, and the vendor was contacted early about the disclosure.","solution":"N/A -- no mitigation discussed in source.","labels":["security"],"sourceUrl":"https://github.com/advisories/GHSA-c693-x898-5g4h","publishedAt":"2026-06-21T12:30:52.000Z","cveId":"CVE-2026-12798","cweIds":["CWE-918"],"cvssScore":"6.3","cvssSeverity":"low","severity":"low","attackType":["other"],"issueType":"vulnerability","affectedPackages":["litellm@<= 1.82.2"],"affectedPackageNames":["litellm"],"affectedPackageRefs":["pypi:litellm"],"affectedVendors":[],"affectedVendorsRaw":["LiteLLM","MCP OpenAPI Spec Loader"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","summaryPromptVersion":"v2","headline":null,"headlinePromptVersion":null,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","attackVector":"network","attackComplexity":"low","privilegesRequired":"low","userInteraction":"none","exploitMaturity":"unknown","epssScore":0.004,"epssCheckedAt":"2026-10-10T04:57:20.982Z","kevDateAdded":null,"advisoryAliases":["GHSA-c693-x898-5g4h"],"affectedPackagesSource":null,"affectedPackagesCheckedAt":null,"patchAvailable":null,"disclosureDate":"2026-06-21T12:30:52.000Z","capecIds":["CAPEC-664"],"crossRefCount":0,"attackSophistication":"trivial","impactType":["confidentiality","integrity"],"aiComponentTargeted":"api","llmSpecific":false,"classifierConfidence":0.85,"researchCategory":null,"atlasIds":null}}