{"data":{"id":"6a471bd6-9303-4104-a48a-057edc603d73","title":"GHSA-qmf3-4767-5fg3: LiteLLM: M2M JWT Handler Has Improper Authorization","summary":"A vulnerability in BerriAI litellm up to 1.82.2 affects an unknown function in litellm/proxy/auth/user_api_key_auth.py, part of the M2M JWT Handler component. It leads to improper authorization and can be launched remotely, though the attack complexity is high and exploitability is reported as difficult. A public exploit is available and might be used, and the vendor was contacted early about the disclosure.","solution":"N/A -- no mitigation discussed in source.","labels":["security"],"sourceUrl":"https://github.com/advisories/GHSA-qmf3-4767-5fg3","publishedAt":"2026-06-21T03:30:24.000Z","cveId":"CVE-2026-12771","cweIds":["CWE-266","CWE-285"],"cvssScore":"5","cvssSeverity":"low","severity":"low","attackType":["other"],"issueType":"vulnerability","affectedPackages":["litellm@<= 1.82.2"],"affectedPackageNames":["litellm"],"affectedPackageRefs":["pypi:litellm"],"affectedVendors":[],"affectedVendorsRaw":["LiteLLM"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","summaryPromptVersion":"v2","headline":null,"headlinePromptVersion":null,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L","attackVector":"network","attackComplexity":"high","privilegesRequired":"low","userInteraction":"none","exploitMaturity":"unknown","epssScore":0.00431,"epssCheckedAt":"2026-10-10T04:57:19.152Z","kevDateAdded":null,"advisoryAliases":["GHSA-qmf3-4767-5fg3"],"affectedPackagesSource":null,"affectedPackagesCheckedAt":null,"patchAvailable":null,"disclosureDate":"2026-06-21T03:30:24.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"advanced","impactType":["confidentiality","integrity"],"aiComponentTargeted":"api","llmSpecific":true,"classifierConfidence":0.95,"researchCategory":null,"atlasIds":null}}