{"data":{"id":"991fb14c-4b21-41cf-80a2-4f9cad5ec832","title":"GHSA-p897-vf7j-f5h8: BerriAI litellm has Security Feature Bypass in BannedKeywords and AzureContentSafety Guardrails via call_type Mismatch on Async Endpoints","summary":"A flaw in BerriAI litellm up to 1.82.5 affects the async_pre_call_hook function in enterprise/enterprise_hooks/banned_keywords.py, part of the Completions Interface. Manipulating the prompt argument results in incorrect authorization, and the attack can be carried out remotely. A public exploit has been released, and the vendor was contacted early about the disclosure.","solution":"N/A -- no mitigation discussed in source.","labels":["security"],"sourceUrl":"https://github.com/advisories/GHSA-p897-vf7j-f5h8","publishedAt":"2026-06-21T12:30:52.000Z","cveId":"CVE-2026-12797","cweIds":["CWE-285"],"cvssScore":"6.3","cvssSeverity":"low","severity":"low","attackType":["jailbreak"],"issueType":"vulnerability","affectedPackages":["litellm@<= 1.82.5"],"affectedPackageNames":["litellm"],"affectedPackageRefs":["pypi:litellm"],"affectedVendors":[],"affectedVendorsRaw":["litellm"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","summaryPromptVersion":"v2","headline":null,"headlinePromptVersion":null,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","attackVector":"network","attackComplexity":"low","privilegesRequired":"low","userInteraction":"none","exploitMaturity":"unknown","epssScore":0.004,"epssCheckedAt":"2026-10-10T04:57:20.680Z","kevDateAdded":null,"advisoryAliases":["GHSA-p897-vf7j-f5h8"],"affectedPackagesSource":null,"affectedPackagesCheckedAt":null,"patchAvailable":null,"disclosureDate":"2026-06-21T12:30:52.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"trivial","impactType":["integrity","safety"],"aiComponentTargeted":"api","llmSpecific":true,"classifierConfidence":0.85,"researchCategory":null,"atlasIds":["AML.T0054"]}}