{"data":{"id":"9c7f7db8-add9-4e56-b904-890d8475a104","title":"GHSA-4jcj-7x88-m979: LiteLLM: MCP Proxy Has Improper Authentication","summary":"A weakness in BerriAI litellm up to 1.59.8 affects the function UserAPIKeyAuth in litellm/proxy/_experimental/mcp_server/auth/user_api_key_auth_mcp.py, part of the MCP Proxy component. Manipulating this component can lead to improper authentication, and the attack can be launched remotely. A public exploit exists, and the vendor was contacted early about the disclosure.","solution":"N/A -- no mitigation discussed in source.","labels":["security"],"sourceUrl":"https://github.com/advisories/GHSA-4jcj-7x88-m979","publishedAt":"2026-06-21T06:32:07.000Z","cveId":"CVE-2026-12773","cweIds":["CWE-287","CWE-303"],"cvssScore":"7.3","cvssSeverity":"medium","severity":"medium","attackType":["other"],"issueType":"vulnerability","affectedPackages":["litellm@< 1.84.0 (fixed: 1.84.0)"],"affectedPackageNames":["litellm"],"affectedPackageRefs":["pypi:litellm"],"affectedVendors":[],"affectedVendorsRaw":["LiteLLM","BerriAI litellm","MCP Proxy"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","summaryPromptVersion":"v2","headline":null,"headlinePromptVersion":null,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","attackVector":"network","attackComplexity":"low","privilegesRequired":"none","userInteraction":"none","exploitMaturity":"unknown","epssScore":0.01017,"epssCheckedAt":"2026-10-10T04:57:19.782Z","kevDateAdded":null,"advisoryAliases":["GHSA-4jcj-7x88-m979"],"affectedPackagesSource":null,"affectedPackagesCheckedAt":null,"patchAvailable":true,"disclosureDate":"2026-06-21T06:32:07.000Z","capecIds":["CAPEC-114"],"crossRefCount":0,"attackSophistication":"trivial","impactType":["confidentiality","integrity"],"aiComponentTargeted":"api","llmSpecific":true,"classifierConfidence":0.9,"researchCategory":null,"atlasIds":null}}