{"data":{"id":"9cecbe4b-bb65-4b3f-8656-fc7708735008","title":"CVE-2026-108575: A vulnerability has been found in BerriAI LiteLLM up to 1.94.0. This affects the function get_secret of the file…","summary":"A vulnerability has been found in BerriAI LiteLLM up to 1.94.0, in the get_secret function of secret_managers/main.py within the Secret Resolution component. Manipulating the api_key argument leads to improper authorization, and the attack can be initiated remotely. The exploit is public and may be used, and the vendor did not respond after early contact.","solution":"N/A -- no mitigation discussed in source.","labels":["security"],"sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-108575","publishedAt":"2026-10-11T12:16:53.210Z","cveId":"CVE-2026-108575","cweIds":["CWE-266","CWE-285"],"cvssScore":"6.3","cvssSeverity":"medium","severity":"medium","attackType":["other"],"issueType":"vulnerability","affectedPackages":null,"affectedPackageNames":null,"affectedPackageRefs":null,"affectedVendors":["LangChain"],"affectedVendorsRaw":["LiteLLM"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","summaryPromptVersion":"v2","headline":"BerriAI LiteLLM improper authorization in secret resolution via api_key","headlinePromptVersion":"h1","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","attackVector":"network","attackComplexity":"low","privilegesRequired":"low","userInteraction":"none","exploitMaturity":"unknown","epssScore":0,"epssCheckedAt":"2026-10-11T13:09:16.318Z","kevDateAdded":null,"advisoryAliases":["GHSA-gw95-8pcg-7gvv"],"affectedPackagesSource":null,"affectedPackagesCheckedAt":"2026-10-11T13:09:18.809Z","patchAvailable":null,"disclosureDate":"2026-10-11T12:16:53.210Z","capecIds":null,"crossRefCount":0,"attackSophistication":"trivial","impactType":["confidentiality","integrity"],"aiComponentTargeted":"api","llmSpecific":true,"classifierConfidence":0.9,"researchCategory":null,"atlasIds":null}}