{"data":{"id":"d53aa265-4fe5-4ff0-8258-0d2681724968","title":"GHSA-fjcf-3j3r-78rp: LiteLLM Has an Improper Authorization Vulnerability","summary":"An improper authorization flaw in the main-latest version of BerriAI/litellm gives a user with the role 'internal_user_viewer' an overly privileged API key when they log in. That key reaches admin functionality, including endpoints such as '/users/list' and '/users/get_users'. The result is privilege escalation that lets any account become a PROXY ADMIN.","solution":"N/A -- no mitigation discussed in source.","labels":["security"],"sourceUrl":"https://github.com/advisories/GHSA-fjcf-3j3r-78rp","publishedAt":"2025-03-20T12:32:52.000Z","cveId":"CVE-2025-0628","cweIds":["CWE-266","CWE-285"],"cvssScore":"8.1","cvssSeverity":"high","severity":"high","attackType":["other"],"issueType":"vulnerability","affectedPackages":["litellm@< 1.61.15 (fixed: 1.61.15)"],"affectedPackageNames":["litellm"],"affectedPackageRefs":["pypi:litellm"],"affectedVendors":[],"affectedVendorsRaw":["LiteLLM"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","summaryPromptVersion":"v2","headline":null,"headlinePromptVersion":null,"cvssVector":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","attackVector":"network","attackComplexity":"low","privilegesRequired":"low","userInteraction":"none","exploitMaturity":"unknown","epssScore":0.00338,"epssCheckedAt":"2026-10-10T04:57:11.240Z","kevDateAdded":null,"advisoryAliases":["GHSA-fjcf-3j3r-78rp"],"affectedPackagesSource":null,"affectedPackagesCheckedAt":null,"patchAvailable":true,"disclosureDate":"2025-03-20T12:32:52.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"trivial","impactType":["confidentiality","integrity"],"aiComponentTargeted":"api","llmSpecific":true,"classifierConfidence":0.95,"researchCategory":null,"atlasIds":null}}