{"data":{"id":"a3a63140-2fe5-4bef-b4f5-70e1ecc0cd66","title":"GHSA-6qr3-3g89-m4jj: LiteLLM: Admin Key Handler Has Improper Authorization","summary":"A vulnerability in BerriAI litellm up to version 1.63.1 affects an unknown function in litellm/proxy/management_endpoints/key_management_endpoints.py, part of the Admin Key Handler component. It causes improper authorization and can be initiated remotely. The exploit has been publicly disclosed and may be used, and the vendor was contacted early about the disclosure.","solution":"N/A -- no mitigation discussed in source.","labels":["security"],"sourceUrl":"https://github.com/advisories/GHSA-6qr3-3g89-m4jj","publishedAt":"2026-06-21T03:30:24.000Z","cveId":"CVE-2026-12770","cweIds":["CWE-266"],"cvssScore":"5.4","cvssSeverity":"low","severity":"low","attackType":["other"],"issueType":"vulnerability","affectedPackages":["litellm@<= 1.63.1"],"affectedPackageNames":["litellm"],"affectedPackageRefs":["pypi:litellm"],"affectedVendors":[],"affectedVendorsRaw":["LiteLLM"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","summaryPromptVersion":"v2","headline":null,"headlinePromptVersion":null,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L","attackVector":"network","attackComplexity":"low","privilegesRequired":"low","userInteraction":"none","exploitMaturity":"unknown","epssScore":0.00569,"epssCheckedAt":"2026-10-10T04:57:18.855Z","kevDateAdded":null,"advisoryAliases":["GHSA-6qr3-3g89-m4jj"],"affectedPackagesSource":null,"affectedPackagesCheckedAt":null,"patchAvailable":null,"disclosureDate":"2026-06-21T03:30:24.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["integrity","confidentiality"],"aiComponentTargeted":"api","llmSpecific":true,"classifierConfidence":0.9,"researchCategory":null,"atlasIds":null}}