{"data":{"id":"d5808e9a-632c-4e87-96f3-c41307af2a7b","title":"CVE-2026-84377: LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to versions 1.88.6 and 1.96.","summary":"LiteLLM is a proxy server (a middleman program that forwards requests) that lets users call AI language model APIs using OpenAI's format. Before versions 1.88.6 and 1.96.2, authenticated users could trick the proxy into sending secret credentials (like API keys) to a destination they control by exploiting incomplete validation (security checks) in the request processing code.","solution":"Update LiteLLM to version 1.88.6 or 1.96.2, which fixed the incomplete request validation checks in the proxy code.","labels":["security"],"sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-84377","publishedAt":"2026-09-02T18:21:28.997Z","cveId":"CVE-2026-84377","cweIds":["CWE-918"],"cvssScore":"6.5","cvssSeverity":"medium","severity":"medium","attackType":["supply_chain"],"issueType":"vulnerability","affectedPackages":null,"affectedVendors":["LangChain"],"affectedVendorsRaw":["LiteLLM","OpenAI"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","attackVector":"network","attackComplexity":"low","privilegesRequired":"low","userInteraction":"none","exploitMaturity":"unknown","epssScore":0,"patchAvailable":null,"disclosureDate":"2026-09-02T18:21:28.997Z","capecIds":["CAPEC-664"],"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality","integrity"],"aiComponentTargeted":"api","llmSpecific":true,"classifierConfidence":0.92,"researchCategory":null,"atlasIds":["AML.T0010"]}}