{"data":{"ecosystem":"pypi","name":"litellm","url":"https://aisecwatch.com/packages/pypi/litellm","latestVersion":"1.104.2","firstReleaseAt":"2023-07-27T00:36:16.462Z","repository":"https://github.com/BerriAI/litellm","llm":{"exposure":"direct","depth":0,"integratedAt":"2023-07-27T00:36:16.462Z","integratedVersion":"0.1.0","sdks":["litellm"],"path":[]},"authority":{"profile":["execution","http","mcp_tools"],"fromDependencies":["pypi:aiohttp","pypi:httpx","pypi:mcp","pypi:requests","pypi:restrictedpython"]},"dependencies":[{"ecosystem":"pypi","name":"anthropic","versionSpec":"<1.0,>=0.84.0","scope":"extra:proxy-runtime"},{"ecosystem":"pypi","name":"google-cloud-aiplatform","versionSpec":"<2.0,>=1.133.0","scope":"extra:google"},{"ecosystem":"pypi","name":"google-genai","versionSpec":"<2.0,>=1.37.0","scope":"extra:proxy-runtime"},{"ecosystem":"pypi","name":"huggingface-hub","versionSpec":"<2.0,>=0.34.0","scope":"runtime"},{"ecosystem":"pypi","name":"llm-sandbox","versionSpec":"<1.0,>=0.3.39","scope":"extra:proxy-runtime"},{"ecosystem":"pypi","name":"mcp","versionSpec":"<3,>=2.2.0","scope":"extra:proxy"},{"ecosystem":"pypi","name":"mlflow","versionSpec":"<4.0,>=3.11.1","scope":"extra:mlflow"},{"ecosystem":"pypi","name":"openai","versionSpec":"<3.0.0,>=2.20.0","scope":"runtime"},{"ecosystem":"pypi","name":"redisvl","versionSpec":"<1.0,>=0.4.1","scope":"extra:extra-proxy"},{"ecosystem":"pypi","name":"semantic-router","versionSpec":"<1.0,>=0.1.15","scope":"extra:semantic-router"},{"ecosystem":"pypi","name":"sentry-sdk","versionSpec":"<3.0,>=2.21.0","scope":"extra:proxy-runtime"},{"ecosystem":"pypi","name":"tokenizers","versionSpec":"<1.0,>=0.21.0","scope":"runtime"},{"ecosystem":"pypi","name":"a2a-sdk","versionSpec":"<2.0,>=1.1.0","scope":"extra:extra-proxy"},{"ecosystem":"pypi","name":"aiohttp","versionSpec":"<4.0,>=3.14.2","scope":"runtime"},{"ecosystem":"pypi","name":"apscheduler","versionSpec":"<4.0,>=3.11.2","scope":"extra:proxy"},{"ecosystem":"pypi","name":"audioread","versionSpec":">=3.0.1","scope":"extra:stt-nvidia-riva"},{"ecosystem":"pypi","name":"aurelio-sdk","versionSpec":"<1.0,>=0.0.19","scope":"extra:semantic-router"},{"ecosystem":"pypi","name":"aws-sdk-bedrock-runtime","versionSpec":"<0.12.0,>=0.10.0","scope":"extra:bedrock-realtime"},{"ecosystem":"pypi","name":"azure-ai-contentsafety","versionSpec":"<2.0,>=1.0.0","scope":"extra:proxy-runtime"},{"ecosystem":"pypi","name":"azure-identity","versionSpec":"<2.0,>=1.25.2","scope":"extra:proxy"},{"ecosystem":"pypi","name":"azure-keyvault-secrets","versionSpec":"<5.0,>=4.10.0","scope":"extra:extra-proxy"},{"ecosystem":"pypi","name":"azure-storage-blob","versionSpec":"<13.0,>=12.28.0","scope":"extra:proxy"},{"ecosystem":"pypi","name":"azure-storage-file-datalake","versionSpec":"<13.0,>=12.20.0","scope":"extra:proxy-runtime"},{"ecosystem":"pypi","name":"backoff","versionSpec":"<3.0,>=2.2.1","scope":"extra:proxy"},{"ecosystem":"pypi","name":"boto3","versionSpec":"<2.0,>=1.43.1","scope":"runtime"},{"ecosystem":"pypi","name":"click","versionSpec":"<9.0,>=8.0.0","scope":"runtime"},{"ecosystem":"pypi","name":"cryptography","versionSpec":"<51.0,>=49.0.0","scope":"extra:proxy"},{"ecosystem":"pypi","name":"ddtrace","versionSpec":"<5.0,>=4.8.2","scope":"extra:proxy-runtime"},{"ecosystem":"pypi","name":"detect-secrets","versionSpec":"<2.0,>=1.5.0","scope":"extra:proxy-runtime"},{"ecosystem":"pypi","name":"diskcache","versionSpec":"<6.0,>=5.6.3","scope":"extra:caching"},{"ecosystem":"pypi","name":"expression","versionSpec":"<6.0,>=5.6.0","scope":"extra:proxy"},{"ecosystem":"pypi","name":"fastapi","versionSpec":"<1.0,>=0.136.3","scope":"extra:proxy"},{"ecosystem":"pypi","name":"fastapi-sso","versionSpec":"<1.0,>=0.19.0","scope":"extra:proxy"},{"ecosystem":"pypi","name":"fastuuid","versionSpec":"<1.0,>=0.14.0","scope":"runtime"},{"ecosystem":"pypi","name":"filelock","versionSpec":"<4.0,>=3.16.1","scope":"runtime"},{"ecosystem":"pypi","name":"google-cloud-iam","versionSpec":"<3.0,>=2.19.1","scope":"extra:extra-proxy"},{"ecosystem":"pypi","name":"google-cloud-kms","versionSpec":"<3.0,>=2.24.2","scope":"extra:extra-proxy"},{"ecosystem":"pypi","name":"google-cloud-speech","versionSpec":"<3.0,>=2.40.0","scope":"extra:stt-vertex-chirp"},{"ecosystem":"pypi","name":"granian","versionSpec":"<3.0,>=2.7.4","scope":"extra:proxy"},{"ecosystem":"pypi","name":"grpcio","versionSpec":"==1.78.0","scope":"extra:grpc"},{"ecosystem":"pypi","name":"gunicorn","versionSpec":"<24.0,>=23.0.0","scope":"extra:proxy"},{"ecosystem":"pypi","name":"hiredis","versionSpec":"<4.0,>=3.0.0","scope":"extra:proxy"},{"ecosystem":"pypi","name":"httpx","versionSpec":"<1.0,>=0.28.0","scope":"runtime"},{"ecosystem":"pypi","name":"httpx2","versionSpec":"<3,>=2.5.0","scope":"extra:proxy"},{"ecosystem":"pypi","name":"importlib-metadata","versionSpec":"<9.0,>=8.0.0","scope":"runtime"},{"ecosystem":"pypi","name":"inquirerpy","versionSpec":"<1.0,>=0.3.4","scope":"extra:proxy"},{"ecosystem":"pypi","name":"jinja2","versionSpec":"<4.0,>=3.1.6","scope":"runtime"},{"ecosystem":"pypi","name":"jsonschema","versionSpec":"<5.0,>=4.0.0","scope":"runtime"},{"ecosystem":"pypi","name":"keyring","versionSpec":"<26.0,>=25.6.0","scope":"extra:cli"},{"ecosystem":"pypi","name":"langfuse","versionSpec":"<5.0,>=4.7","scope":"extra:proxy-runtime"},{"ecosystem":"pypi","name":"litellm-enterprise","versionSpec":"==0.1.71","scope":"extra:proxy"},{"ecosystem":"pypi","name":"litellm-proxy-extras","versionSpec":"==0.4.102.post1","scope":"extra:proxy"},{"ecosystem":"pypi","name":"mangum","versionSpec":"<1.0,>=0.17.0","scope":"extra:proxy-runtime"},{"ecosystem":"pypi","name":"numpy","versionSpec":">=1.26.0","scope":"extra:stt-nvidia-riva"},{"ecosystem":"pypi","name":"numpydoc","versionSpec":"<2.0,>=1.8.0","scope":"extra:utils"},{"ecosystem":"pypi","name":"nvidia-riva-client","versionSpec":">=2.15.0","scope":"extra:stt-nvidia-riva"},{"ecosystem":"pypi","name":"opentelemetry-api","versionSpec":"==1.33.1","scope":"extra:proxy-runtime"},{"ecosystem":"pypi","name":"opentelemetry-exporter-otlp","versionSpec":"==1.33.1","scope":"extra:proxy-runtime"},{"ecosystem":"pypi","name":"opentelemetry-instrumentation-fastapi","versionSpec":"==0.54b1","scope":"extra:proxy-runtime"},{"ecosystem":"pypi","name":"opentelemetry-sdk","versionSpec":"==1.33.1","scope":"extra:proxy-runtime"},{"ecosystem":"pypi","name":"orjson","versionSpec":"<4.0,>=3.11.6","scope":"extra:proxy"},{"ecosystem":"pypi","name":"packaging","versionSpec":">=24.0","scope":"runtime"},{"ecosystem":"pypi","name":"polars","versionSpec":"<2.0,>=1.38.1","scope":"extra:proxy"},{"ecosystem":"pypi","name":"prisma","versionSpec":"<1.0,>=0.11.0","scope":"extra:extra-proxy"},{"ecosystem":"pypi","name":"prometheus-client","versionSpec":"<1.0,>=0.20.0","scope":"extra:proxy-runtime"},{"ecosystem":"pypi","name":"psycopg","versionSpec":"<4.0,>=3.2","scope":"extra:extra-proxy"},{"ecosystem":"pypi","name":"psycopg-binary","versionSpec":"<4.0,>=3.2","scope":"extra:extra-proxy"},{"ecosystem":"pypi","name":"pydantic","versionSpec":"<3.0.0,>=2.11.0","scope":"runtime"},{"ecosystem":"pypi","name":"pydantic-settings","versionSpec":"<3.0,>=2.14.1","scope":"runtime"},{"ecosystem":"pypi","name":"pyjwt","versionSpec":"<3.0,>=2.13.0","scope":"extra:proxy"},{"ecosystem":"pypi","name":"pynacl","versionSpec":"<2.0,>=1.6.2","scope":"extra:proxy"},{"ecosystem":"pypi","name":"pypdf","versionSpec":"<7.0,>=6.16.1","scope":"extra:proxy-runtime"},{"ecosystem":"pypi","name":"pyroscope-io","versionSpec":"<1.0,>=0.8.16","scope":"extra:proxy"},{"ecosystem":"pypi","name":"python3-saml","versionSpec":"<2.0,>=1.16.0","scope":"extra:saml"},{"ecosystem":"pypi","name":"python-dotenv","versionSpec":"<2.0,>=1.0.0","scope":"runtime"},{"ecosystem":"pypi","name":"python-multipart","versionSpec":"<1.0,>=0.0.27","scope":"extra:proxy"},{"ecosystem":"pypi","name":"pyyaml","versionSpec":"<7.0,>=6.0.3","scope":"runtime"},{"ecosystem":"pypi","name":"requests","versionSpec":"<3.0,>=2.32.0","scope":"extra:cli"},{"ecosystem":"pypi","name":"resend","versionSpec":"<3.0,>=2.23.0","scope":"extra:extra-proxy"},{"ecosystem":"pypi","name":"restrictedpython","versionSpec":"<9.0,>=8.5","scope":"extra:proxy"},{"ecosystem":"pypi","name":"rich","versionSpec":"<14.0,>=13.9.4","scope":"extra:proxy"},{"ecosystem":"pypi","name":"rq","versionSpec":"<3.0,>=2.7.0","scope":"extra:proxy"},{"ecosystem":"pypi","name":"soundfile","versionSpec":"<1.0,>=0.12.1","scope":"extra:proxy"},{"ecosystem":"pypi","name":"starlette","versionSpec":"<2.0,>=1.0.1","scope":"extra:proxy"},{"ecosystem":"pypi","name":"tiktoken","versionSpec":"<1.0,>=0.8.0","scope":"runtime"},{"ecosystem":"pypi","name":"tomlkit","versionSpec":"<1.0,>=0.13.3","scope":"extra:proxy"},{"ecosystem":"pypi","name":"uvicorn","versionSpec":"<1.0,>=0.33.0","scope":"extra:proxy"},{"ecosystem":"pypi","name":"uvloop","versionSpec":"<1.0,>=0.22.1","scope":"extra:proxy"},{"ecosystem":"pypi","name":"websockets","versionSpec":"<16.0,>=15.0.1","scope":"extra:proxy"}],"advisories":[{"id":"27715b13-4175-41fd-8ca6-7e074e00759e","url":"https://aisecwatch.com/issues/27715b13-4175-41fd-8ca6-7e074e00759e","cveId":"CVE-2026-59823","title":"CVE-2026-59823: LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.9, an authenticated…","headline":"LiteLLM Proxy server-side request forgery through user_config api_base","severity":"high","publishedAt":"2026-09-16T19:17:21.377Z","affected":["litellm@<= 1.83.8 (fixed: 1.83.9)"],"epssScore":0.00439,"matchedBy":"ecosystem"},{"id":"d5808e9a-632c-4e87-96f3-c41307af2a7b","url":"https://aisecwatch.com/issues/d5808e9a-632c-4e87-96f3-c41307af2a7b","cveId":"CVE-2026-84377","title":"CVE-2026-84377: LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to versions 1.88.6 and…","headline":"LiteLLM proxy credential exposure through unchecked api_base redirection","severity":"medium","publishedAt":"2026-09-02T18:21:28.997Z","affected":["litellm@< 1.88.6 (fixed: 1.88.6)","litellm@>= 1.89.0, < 1.89.7 (fixed: 1.89.7)","litellm@>= 1.90.0, < 1.90.7 (fixed: 1.90.7)","litellm@>= 1.91.0, < 1.91.5 (fixed: 1.91.5)","litellm@>= 1.92.0, < 1.92.2 (fixed: 1.92.2)","litellm@>= 1.93.0, < 1.93.2 (fixed: 1.93.2)","litellm@>= 1.94.0, < 1.94.3 (fixed: 1.94.3)","litellm@>= 1.95.0, < 1.95.1 (fixed: 1.95.1)","litellm@>= 1.96.0, < 1.96.2 (fixed: 1.96.2)"],"epssScore":0.0054,"matchedBy":"ecosystem"},{"id":"531a35bd-4eda-45bd-abd4-a2d3e5448144","url":"https://aisecwatch.com/issues/531a35bd-4eda-45bd-abd4-a2d3e5448144","cveId":"CVE-2026-37004","title":"CVE-2026-37004: BerriAI litellm <=1.82.4 is vulnerable to Server-Side Template Injection (SSTI), which allows unauthenticated remote…","headline":"LiteLLM unauthenticated command execution via template injection","severity":"critical","publishedAt":"2026-08-27T20:17:41.270Z","affected":["litellm@< 1.83.7 (fixed: 1.83.7)"],"epssScore":0.00799,"matchedBy":"ecosystem"},{"id":"127a3c50-f7c1-48e7-8a00-2ab47b9d3cc9","url":"https://aisecwatch.com/issues/127a3c50-f7c1-48e7-8a00-2ab47b9d3cc9","cveId":"CVE-2026-59822","title":"CVE-2026-59822: LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.84.0, LiteLLM's MCP…","headline":"LiteLLM authentication bypass through MCP Streamable HTTP endpoint","severity":"high","publishedAt":"2026-07-08T20:16:57.683Z","affected":["litellm@< 1.84.0 (fixed: 1.84.0)"],"epssScore":0.00836,"matchedBy":"ecosystem"},{"id":"d6c3db4f-9a84-4fc0-bb41-e65c031538f1","url":"https://aisecwatch.com/issues/d6c3db4f-9a84-4fc0-bb41-e65c031538f1","cveId":"CVE-2026-59821","title":"CVE-2026-59821: LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.82.0-stable, LiteLLM's…","headline":"LiteLLM code injection through Custom Code Guardrails create and update","severity":"low","publishedAt":"2026-07-08T20:16:57.547Z","affected":["litellm@< 1.82.0 (fixed: 1.82.0)"],"epssScore":0.00904,"matchedBy":"ecosystem"},{"id":"a5e042ad-8af0-4730-84b8-2b1d85aba7e7","url":"https://aisecwatch.com/issues/a5e042ad-8af0-4730-84b8-2b1d85aba7e7","cveId":"CVE-2026-59820","title":"CVE-2026-59820: LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.7-stable, LiteLLM…","headline":"LiteLLM path traversal in Skills archive extraction via uploaded ZIP","severity":"high","publishedAt":"2026-07-08T20:16:57.413Z","affected":["litellm@< 1.83.7 (fixed: 1.83.7)"],"epssScore":0.00587,"matchedBy":"ecosystem"},{"id":"d0b006b1-ae2e-4097-8158-3af83d020747","url":"https://aisecwatch.com/issues/d0b006b1-ae2e-4097-8158-3af83d020747","cveId":"CVE-2026-59819","title":"CVE-2026-59819: LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.10-stable…","headline":"LiteLLM file read through /health/test_connection endpoint","severity":"low","publishedAt":"2026-07-08T20:16:57.277Z","affected":["litellm@< 1.83.10 (fixed: 1.83.10)"],"epssScore":0.00572,"matchedBy":"ecosystem"},{"id":"6137cd12-9077-47c6-ae09-65276f19b7cc","url":"https://aisecwatch.com/issues/6137cd12-9077-47c6-ae09-65276f19b7cc","cveId":"CVE-2026-12798","title":"GHSA-c693-x898-5g4h: BerriAI litellm has SSRF via Unvalidated spec_path URL in MCP OpenAPI Spec Loader","headline":null,"severity":"low","publishedAt":"2026-06-21T12:30:52.000Z","affected":["litellm@<= 1.82.2"],"epssScore":0.004,"matchedBy":"ecosystem"},{"id":"991fb14c-4b21-41cf-80a2-4f9cad5ec832","url":"https://aisecwatch.com/issues/991fb14c-4b21-41cf-80a2-4f9cad5ec832","cveId":"CVE-2026-12797","title":"GHSA-p897-vf7j-f5h8: BerriAI litellm has Security Feature Bypass in BannedKeywords and AzureContentSafety Guardrails via call_type Mismatch on Async Endpoints","headline":null,"severity":"low","publishedAt":"2026-06-21T12:30:52.000Z","affected":["litellm@<= 1.82.5"],"epssScore":0.004,"matchedBy":"ecosystem"},{"id":"a7dab688-d039-4883-9f74-503660e01b99","url":"https://aisecwatch.com/issues/a7dab688-d039-4883-9f74-503660e01b99","cveId":"CVE-2026-12796","title":"GHSA-w2mh-qq9q-453x: BerriAI litellm: SSO Login Does Not Invalidate Previous UI Session Tokens","headline":null,"severity":"low","publishedAt":"2026-06-21T12:30:52.000Z","affected":["litellm@<= 1.82.2"],"epssScore":0.0057,"matchedBy":"ecosystem"},{"id":"833a9504-ba3e-4edb-be49-dd2eb6d4758c","url":"https://aisecwatch.com/issues/833a9504-ba3e-4edb-be49-dd2eb6d4758c","cveId":"CVE-2026-12799","title":"GHSA-m2v5-74w2-qhcj: BerriAI litellm: UI User Enumeration leads to System-Wide Information Disclosure","headline":null,"severity":"low","publishedAt":"2026-06-21T12:30:52.000Z","affected":["litellm@<= 1.82.2"],"epssScore":0.00426,"matchedBy":"ecosystem"},{"id":"2c95e681-7145-43c6-ad35-053819943d13","url":"https://aisecwatch.com/issues/2c95e681-7145-43c6-ad35-053819943d13","cveId":"CVE-2026-12795","title":"GHSA-j37q-q7p9-vpwm: LiteLLM: SSO Debug Flow Has Improper Authentication","headline":null,"severity":"medium","publishedAt":"2026-06-21T09:30:51.000Z","affected":["litellm@<= 1.82.2"],"epssScore":0.00795,"matchedBy":"ecosystem"},{"id":"9c7f7db8-add9-4e56-b904-890d8475a104","url":"https://aisecwatch.com/issues/9c7f7db8-add9-4e56-b904-890d8475a104","cveId":"CVE-2026-12773","title":"GHSA-4jcj-7x88-m979: LiteLLM: MCP Proxy Has Improper Authentication","headline":null,"severity":"medium","publishedAt":"2026-06-21T06:32:07.000Z","affected":["litellm@< 1.84.0 (fixed: 1.84.0)"],"epssScore":0.01017,"matchedBy":"ecosystem"},{"id":"6a471bd6-9303-4104-a48a-057edc603d73","url":"https://aisecwatch.com/issues/6a471bd6-9303-4104-a48a-057edc603d73","cveId":"CVE-2026-12771","title":"GHSA-qmf3-4767-5fg3: LiteLLM: M2M JWT Handler Has Improper Authorization","headline":null,"severity":"low","publishedAt":"2026-06-21T03:30:24.000Z","affected":["litellm@<= 1.82.2"],"epssScore":0.00431,"matchedBy":"ecosystem"},{"id":"def536be-376b-4001-a213-8aa442711cc7","url":"https://aisecwatch.com/issues/def536be-376b-4001-a213-8aa442711cc7","cveId":"CVE-2026-12772","title":"GHSA-mf52-j94g-746m: LiteLLM: PROXY_ADMIN database API Key Generator Has Insufficient Session Expiration","headline":null,"severity":"low","publishedAt":"2026-06-21T03:30:24.000Z","affected":["litellm@<= 1.82.2"],"epssScore":0.004,"matchedBy":"ecosystem"},{"id":"a3a63140-2fe5-4bef-b4f5-70e1ecc0cd66","url":"https://aisecwatch.com/issues/a3a63140-2fe5-4bef-b4f5-70e1ecc0cd66","cveId":"CVE-2026-12770","title":"GHSA-6qr3-3g89-m4jj: LiteLLM: Admin Key Handler Has Improper Authorization","headline":null,"severity":"low","publishedAt":"2026-06-21T03:30:24.000Z","affected":["litellm@<= 1.63.1"],"epssScore":0.00569,"matchedBy":"ecosystem"},{"id":"d80bf98f-7458-42da-80ba-ca10684fc972","url":"https://aisecwatch.com/issues/d80bf98f-7458-42da-80ba-ca10684fc972","cveId":"CVE-2026-49468","title":"GHSA-4xpc-pv4p-pm3w: LiteLLM: Authentication Bypass via Host Header Injection","headline":null,"severity":"critical","publishedAt":"2026-06-16T23:38:26.000Z","affected":["litellm@< 1.84.0 (fixed: 1.84.0)"],"epssScore":0.03033,"matchedBy":"ecosystem"},{"id":"fe931aed-c057-48e2-9982-d61538ec25d3","url":"https://aisecwatch.com/issues/fe931aed-c057-48e2-9982-d61538ec25d3","cveId":"CVE-2026-47102","title":"CVE-2026-47102: LiteLLM prior to 1.83.10 allows a user to modify their own user_role via the /user/update endpoint. While the endpoint…","headline":"LiteLLM self-service user update allows changing own user_role via /user/update","severity":"high","publishedAt":"2026-05-21T21:16:32.557Z","affected":["litellm@< 1.83.10 (fixed: 1.83.10)"],"epssScore":0.00821,"matchedBy":"ecosystem"},{"id":"b625009a-a9c7-42ef-86fd-06b57ea4685f","url":"https://aisecwatch.com/issues/b625009a-a9c7-42ef-86fd-06b57ea4685f","cveId":"CVE-2026-47101","title":"CVE-2026-47101: LiteLLM prior to 1.83.14 allows an authenticated internal_user to create API keys with access to routes that their role…","headline":"LiteLLM API key creation bypasses role-based route restrictions","severity":"high","publishedAt":"2026-05-21T21:16:32.413Z","affected":["litellm@< 1.83.14 (fixed: 1.83.14)"],"epssScore":0.01331,"matchedBy":"ecosystem"},{"id":"73d45422-1393-4ae4-8177-49bde0732f13","url":"https://aisecwatch.com/issues/73d45422-1393-4ae4-8177-49bde0732f13","cveId":"CVE-2026-42271","title":"CVE-2026-42271: LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.74.2 to before…","headline":"LiteLLM command execution through MCP test endpoints","severity":"critical","publishedAt":"2026-05-08T04:16:21.820Z","affected":["litellm@>= 1.74.2, < 1.83.7 (fixed: 1.83.7)"],"epssScore":0.9257,"matchedBy":"ecosystem"},{"id":"4aa4b69f-c572-4a35-9559-c435845176b7","url":"https://aisecwatch.com/issues/4aa4b69f-c572-4a35-9559-c435845176b7","cveId":"CVE-2026-42208","title":"CVE-2026-42208: LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.81.16 to before…","headline":null,"severity":"critical","publishedAt":"2026-05-08T04:16:19.923Z","affected":["litellm@>= 1.81.16, < 1.83.7 (fixed: 1.83.7)"],"epssScore":0.05772,"matchedBy":"ecosystem"},{"id":"0fd02a0d-7bf5-45bd-be7c-ff62381e18a4","url":"https://aisecwatch.com/issues/0fd02a0d-7bf5-45bd-be7c-ff62381e18a4","cveId":"CVE-2026-42203","title":"CVE-2026-42203: LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.80.5 to before…","headline":"LiteLLM code execution through prompt template rendering in /prompts/test","severity":"critical","publishedAt":"2026-05-08T04:16:19.450Z","affected":["litellm@>= 1.80.5, < 1.83.7 (fixed: 1.83.7)"],"epssScore":0.00664,"matchedBy":"ecosystem"},{"id":"5e30a949-c58c-4def-bfdb-5d248a178887","url":"https://aisecwatch.com/issues/5e30a949-c58c-4def-bfdb-5d248a178887","cveId":null,"title":"GHSA-v4p8-mg3p-g94g: LiteLLM: Authenticated command execution via MCP stdio test endpoints","headline":null,"severity":"high","publishedAt":"2026-04-25T23:27:54.000Z","affected":["litellm@>= 1.74.2, < 1.83.7 (fixed: 1.83.7)"],"epssScore":null,"matchedBy":"ecosystem"},{"id":"4e7b8ba3-978d-4866-b04f-dc716f6e17cd","url":"https://aisecwatch.com/issues/4e7b8ba3-978d-4866-b04f-dc716f6e17cd","cveId":null,"title":"GHSA-r75f-5x8p-qvmc: LiteLLM has SQL Injection in Proxy API key verification","headline":null,"severity":"critical","publishedAt":"2026-04-24T16:17:07.000Z","affected":["litellm@>= 1.81.16, < 1.83.7 (fixed: 1.83.7)"],"epssScore":null,"matchedBy":"ecosystem"},{"id":"128ebf5f-466f-4816-870c-9f727681933d","url":"https://aisecwatch.com/issues/128ebf5f-466f-4816-870c-9f727681933d","cveId":null,"title":"GHSA-xqmj-j6mv-4862: LiteLLM: Server-Side Template Injection in /prompts/test endpoint","headline":null,"severity":"high","publishedAt":"2026-04-24T16:02:42.000Z","affected":["litellm@>= 1.80.5, < 1.83.7 (fixed: 1.83.7)"],"epssScore":null,"matchedBy":"ecosystem"},{"id":"af9c461c-a222-446a-8dee-20f07e6bf9af","url":"https://aisecwatch.com/issues/af9c461c-a222-446a-8dee-20f07e6bf9af","cveId":"CVE-2026-40217","title":"CVE-2026-40217: LiteLLM through 2026-04-08 allows remote attackers to execute arbitrary code via bytecode rewriting at the…","headline":"LiteLLM remote code execution at /guardrails/test_custom_code","severity":"high","publishedAt":"2026-04-10T14:16:36.307Z","affected":["litellm@>= 1.81.8, < 1.83.10 (fixed: 1.83.10)"],"epssScore":0.03399,"matchedBy":"ecosystem"},{"id":"48a686d9-2c15-4ca1-9f94-f3efdcf252d3","url":"https://aisecwatch.com/issues/48a686d9-2c15-4ca1-9f94-f3efdcf252d3","cveId":null,"title":"GHSA-69x8-hrgq-fjj8: LiteLLM: Password hash exposure and pass-the-hash authentication bypass","headline":null,"severity":"high","publishedAt":"2026-04-08T00:04:12.000Z","affected":["litellm@< 1.83.0 (fixed: 1.83.0)"],"epssScore":null,"matchedBy":"ecosystem"},{"id":"85e9dc1d-074e-468e-bff2-903d2873233e","url":"https://aisecwatch.com/issues/85e9dc1d-074e-468e-bff2-903d2873233e","cveId":"CVE-2026-35030","title":"GHSA-jjhc-v7c2-5hh6: LiteLLM: Authentication bypass via OIDC userinfo cache key collision","headline":null,"severity":"critical","publishedAt":"2026-04-03T21:59:50.000Z","affected":["litellm@< 1.83.0 (fixed: 1.83.0)"],"epssScore":0.00879,"matchedBy":"ecosystem"},{"id":"c57dc938-18b1-43b1-a5cc-2844e859e4b0","url":"https://aisecwatch.com/issues/c57dc938-18b1-43b1-a5cc-2844e859e4b0","cveId":"CVE-2026-35029","title":"GHSA-53mr-6c8q-9789: LiteLLM: Privilege escalation via unrestricted proxy configuration endpoint","headline":null,"severity":"high","publishedAt":"2026-04-03T21:59:31.000Z","affected":["litellm@< 1.83.0 (fixed: 1.83.0)"],"epssScore":0.03982,"matchedBy":"ecosystem"},{"id":"30991065-d699-41a5-8e41-3b961942dd93","url":"https://aisecwatch.com/issues/30991065-d699-41a5-8e41-3b961942dd93","cveId":null,"title":"GHSA-5mg7-485q-xm76: Two LiteLLM versions published containing credential harvesting malware","headline":null,"severity":"critical","publishedAt":"2026-03-25T14:25:42.000Z","affected":["litellm@>= 1.82.7, <= 1.82.8"],"epssScore":null,"matchedBy":"ecosystem"},{"id":"1728611a-ed49-4e79-a448-16db6c63ae6a","url":"https://aisecwatch.com/issues/1728611a-ed49-4e79-a448-16db6c63ae6a","cveId":"CVE-2024-10188","title":"CVE-2024-10188: A vulnerability in BerriAI/litellm, as of commit 26c03c9, allows unauthenticated users to cause a Denial of Service…","headline":"LiteLLM denial of service through unsafe parsing of user input","severity":"medium","publishedAt":"2025-03-20T14:15:14.993Z","affected":["litellm@< 1.53.1.dev1 (fixed: 1.53.1.dev1)"],"epssScore":0.00558,"matchedBy":"ecosystem"},{"id":"d53aa265-4fe5-4ff0-8258-0d2681724968","url":"https://aisecwatch.com/issues/d53aa265-4fe5-4ff0-8258-0d2681724968","cveId":"CVE-2025-0628","title":"GHSA-fjcf-3j3r-78rp: LiteLLM Has an Improper Authorization Vulnerability","headline":null,"severity":"high","publishedAt":"2025-03-20T12:32:52.000Z","affected":["litellm@< 1.61.15 (fixed: 1.61.15)"],"epssScore":0.00338,"matchedBy":"ecosystem"},{"id":"42e6b799-25cd-4211-a4f8-3df0369ee650","url":"https://aisecwatch.com/issues/42e6b799-25cd-4211-a4f8-3df0369ee650","cveId":"CVE-2025-0330","title":"GHSA-879v-fggm-vxw2: LiteLLM Has a Leakage of Langfuse API Keys","headline":null,"severity":"high","publishedAt":"2025-03-20T12:32:52.000Z","affected":["litellm@<= 1.52.1"],"epssScore":0.00555,"matchedBy":"ecosystem"},{"id":"766d9674-6fbc-4c6a-b295-350e77976afd","url":"https://aisecwatch.com/issues/766d9674-6fbc-4c6a-b295-350e77976afd","cveId":"CVE-2024-9606","title":"GHSA-g5pg-73fc-hjwq: LiteLLM Reveals Portion of API Key via a Logging File","headline":null,"severity":"high","publishedAt":"2025-03-20T12:32:51.000Z","affected":["litellm@< 1.44.12 (fixed: 1.44.12)"],"epssScore":0.00752,"matchedBy":"ecosystem"},{"id":"d397fe89-021c-4d79-a86c-731a25d939b9","url":"https://aisecwatch.com/issues/d397fe89-021c-4d79-a86c-731a25d939b9","cveId":"CVE-2024-8984","title":"GHSA-fh2c-86xm-pm2x: LiteLLM Vulnerable to Denial of Service (DoS) via Crafted HTTP Request","headline":null,"severity":"high","publishedAt":"2025-03-20T12:32:49.000Z","affected":["litellm@< 1.56.2 (fixed: 1.56.2)"],"epssScore":0.0084,"matchedBy":"ecosystem"},{"id":"a5c7c8e3-e49b-46f1-be12-656a7ab05876","url":"https://aisecwatch.com/issues/a5c7c8e3-e49b-46f1-be12-656a7ab05876","cveId":"CVE-2024-6825","title":"GHSA-53gh-p8jc-7rg8: LiteLLM Vulnerable to Remote Code Execution (RCE)","headline":null,"severity":"high","publishedAt":"2025-03-20T12:32:45.000Z","affected":["litellm@>= 1.40.3.dev2, <= 1.40.12"],"epssScore":0.0165,"matchedBy":"ecosystem"},{"id":"79143417-530a-4468-b06d-98fcf29ca0f6","url":"https://aisecwatch.com/issues/79143417-530a-4468-b06d-98fcf29ca0f6","cveId":"CVE-2024-6587","title":"CVE-2024-6587: A Server-Side Request Forgery (SSRF) vulnerability exists in berriai/litellm version 1.38.10. This vulnerability allows…","headline":"litellm server-side request forgery through api_base in chat completions","severity":"high","publishedAt":"2024-09-13T20:15:04.637Z","affected":["litellm@< 1.44.8 (fixed: 1.44.8)"],"epssScore":0.35316,"matchedBy":"ecosystem"},{"id":"80c68f99-d939-476e-9ba2-eeba300a0222","url":"https://aisecwatch.com/issues/80c68f99-d939-476e-9ba2-eeba300a0222","cveId":"CVE-2024-5710","title":"GHSA-qqcv-vg9f-5rr3: litellm vulnerable to improper access control in team management","headline":null,"severity":"medium","publishedAt":"2024-06-27T21:32:08.000Z","affected":["litellm@< 1.40.15 (fixed: 1.40.15)"],"epssScore":0.00406,"matchedBy":"ecosystem"},{"id":"a8502e1e-f504-4d17-9891-d8e29d740780","url":"https://aisecwatch.com/issues/a8502e1e-f504-4d17-9891-d8e29d740780","cveId":"CVE-2024-5751","title":"GHSA-gppg-gqw8-wh9g: litellm vulnerable to remote code execution based on using eval unsafely","headline":null,"severity":"critical","publishedAt":"2024-06-27T21:32:08.000Z","affected":["litellm@< 1.40.16 (fixed: 1.40.16)"],"epssScore":0.00882,"matchedBy":"ecosystem"},{"id":"a43a0da3-56f2-4fec-9fcb-bb53168ccf08","url":"https://aisecwatch.com/issues/a43a0da3-56f2-4fec-9fcb-bb53168ccf08","cveId":"CVE-2024-4888","title":"CVE-2024-4888: BerriAI's litellm, in its latest version, is vulnerable to arbitrary file deletion due to improper input validation on…","headline":"BerriAI litellm arbitrary file deletion through /audio/transcriptions endpoint","severity":"high","publishedAt":"2024-06-06T23:16:03.397Z","affected":["litellm@< 1.35.36 (fixed: 1.35.36)"],"epssScore":0.00619,"matchedBy":"ecosystem"},{"id":"16367f09-a707-4eaa-b63d-2c1a56265bbe","url":"https://aisecwatch.com/issues/16367f09-a707-4eaa-b63d-2c1a56265bbe","cveId":"CVE-2024-4890","title":"GHSA-8j42-pcfm-3467: SQL injection in litellm","headline":null,"severity":"medium","publishedAt":"2024-06-06T21:30:37.000Z","affected":["litellm@<= 1.27.14"],"epssScore":0.0056,"matchedBy":"ecosystem"},{"id":"b68fe5d3-c418-43a8-ad55-e80988888949","url":"https://aisecwatch.com/issues/b68fe5d3-c418-43a8-ad55-e80988888949","cveId":"CVE-2024-5225","title":"GHSA-h6m6-jj8v-94jj: SQL injection in litellm","headline":null,"severity":"medium","publishedAt":"2024-06-06T21:30:37.000Z","affected":["litellm@< 1.40.0 (fixed: 1.40.0)"],"epssScore":0.00429,"matchedBy":"ecosystem"},{"id":"94f9dc17-aa5b-4ccc-a34e-3b280e14ed78","url":"https://aisecwatch.com/issues/94f9dc17-aa5b-4ccc-a34e-3b280e14ed78","cveId":"CVE-2024-4264","title":"GHSA-7ggm-4rjg-594w: litellm passes untrusted data to `eval` function without sanitization","headline":null,"severity":"high","publishedAt":"2024-05-18T00:30:42.000Z","affected":["litellm@<= 1.28.11"],"epssScore":0.00883,"matchedBy":"ecosystem"},{"id":"7b90d415-432b-4e75-b43b-e3f66a45eeb6","url":"https://aisecwatch.com/issues/7b90d415-432b-4e75-b43b-e3f66a45eeb6","cveId":"CVE-2024-2952","title":"GHSA-46cm-pfwv-cgf8: LiteLLM has Server-Side Template Injection vulnerability in /completions endpoint","headline":null,"severity":"critical","publishedAt":"2024-04-10T18:30:48.000Z","affected":["litellm@< 1.34.42 (fixed: 1.34.42)"],"epssScore":0.01267,"matchedBy":"ecosystem"}],"checkedAt":"2026-10-09T21:48:43.175Z"},"meta":{"advisoryMatching":"by package name and ecosystem; an advisory with no ecosystem recorded for the package is matched by name alone"}}