{"data":{"id":"833a9504-ba3e-4edb-be49-dd2eb6d4758c","title":"GHSA-m2v5-74w2-qhcj: BerriAI litellm: UI User Enumeration leads to System-Wide Information Disclosure","summary":"A vulnerability in BerriAI litellm up to 1.82.2 lies in the ui_view_users function of litellm/proxy/management_endpoints/internal_user_endpoints.py, tracked as an incomplete fix for CVE-2025-0628. The flaw is an improper authorization issue that can be triggered remotely. The exploit has been publicly disclosed and may be used, and the vendor was contacted early about the disclosure.","solution":"N/A -- no mitigation discussed in source.","labels":["security"],"sourceUrl":"https://github.com/advisories/GHSA-m2v5-74w2-qhcj","publishedAt":"2026-06-21T12:30:52.000Z","cveId":"CVE-2026-12799","cweIds":["CWE-266"],"cvssScore":"4.3","cvssSeverity":"low","severity":"low","attackType":["other"],"issueType":"vulnerability","affectedPackages":["litellm@<= 1.82.2"],"affectedPackageNames":["litellm"],"affectedPackageRefs":["pypi:litellm"],"affectedVendors":[],"affectedVendorsRaw":["LiteLLM"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","summaryPromptVersion":"v2","headline":null,"headlinePromptVersion":null,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","attackVector":"network","attackComplexity":"low","privilegesRequired":"low","userInteraction":"none","exploitMaturity":"unknown","epssScore":0.00426,"epssCheckedAt":"2026-10-10T04:57:21.289Z","kevDateAdded":null,"advisoryAliases":["GHSA-m2v5-74w2-qhcj"],"affectedPackagesSource":null,"affectedPackagesCheckedAt":null,"patchAvailable":null,"disclosureDate":"2026-06-21T12:30:52.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"trivial","impactType":["confidentiality"],"aiComponentTargeted":"api","llmSpecific":true,"classifierConfidence":0.9,"researchCategory":null,"atlasIds":null}}