{"data":{"id":"bca920f9-94a4-4b4f-b2b8-ca1f0ad373c2","title":"CVE-2026-108574: A flaw has been found in BerriAI LiteLLM up to 1.95.0. Affected by this issue is the function…","summary":"A flaw in BerriAI LiteLLM up to 1.95.0 lies in the function ui_view_session_spend_logs in litellm/proxy/spend_tracking/spend_management_endpoints.py, part of the Spend Tracking component. Manipulating the session_id argument leads to authorization bypass, and the attack can be launched remotely. A published exploit exists.","solution":"Upgrade to version 1.96.0, which resolves the issue. The patch is identified as 722d9ffa4f6c5ae15702ab9ab2c5f6bf1688308b.","labels":["security"],"sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-108574","publishedAt":"2026-10-11T12:16:52.990Z","cveId":"CVE-2026-108574","cweIds":["CWE-285","CWE-639"],"cvssScore":"4.3","cvssSeverity":"medium","severity":"medium","attackType":["other"],"issueType":"vulnerability","affectedPackages":null,"affectedPackageNames":null,"affectedPackageRefs":null,"affectedVendors":[],"affectedVendorsRaw":["LiteLLM"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","summaryPromptVersion":"v2","headline":"BerriAI LiteLLM authorization bypass in session spend log view via session_id","headlinePromptVersion":"h1","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","attackVector":"network","attackComplexity":"low","privilegesRequired":"low","userInteraction":"none","exploitMaturity":"unknown","epssScore":0,"epssCheckedAt":"2026-10-11T13:09:16.313Z","kevDateAdded":null,"advisoryAliases":["GHSA-wxjw-vcvf-mvw9"],"affectedPackagesSource":null,"affectedPackagesCheckedAt":"2026-10-11T13:09:19.203Z","patchAvailable":null,"disclosureDate":"2026-10-11T12:16:52.990Z","capecIds":null,"crossRefCount":0,"attackSophistication":"trivial","impactType":["confidentiality","integrity"],"aiComponentTargeted":"api","llmSpecific":true,"classifierConfidence":0.9,"researchCategory":null,"atlasIds":null}}