MediumVulnerabilityLLM-specific
GHSA-j37q-q7p9-vpwm: LiteLLM: SSO Debug Flow Has Improper Authentication
- Identifiers
- CVE-2026-12795GHSA-j37q-q7p9-vpwm
- Published
- Record updated
- Affected
- litellm <= 1.82.2
- Fixed in
- No fixed version was stated when the source was last read.
- Known exploitation
- Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
- EPSS
- 0.8%
Summary
A vulnerability in BerriAI litellm up to version 1.82.2 affects the json.dumps function in litellm/proxy/management_endpoints/ui_sso.py, part of the SSO Debug Flow component. Manipulating this component can lead to missing authentication, and the attack can be executed remotely. The exploit has been publicly disclosed and may be used, and the vendor was contacted early about the disclosure.
Mitigation
The source does not state a fix yet. Check the original advisory for updates.
Affected packages in the Exposure Registry
Matched by package name and ecosystem. Each entry shows whether the package delegates to a language model and how many tracked packages depend on it.
- litellmPyPILLM dependency since 2023-07-27 · 54 tracked dependents
Related items
- HighCVE-2026-106119: LangChain MongoDBChatMessageHistory query injection via session identifierSame vendor · NVD/CVE Database
- LowGHSA-5x6v-p487-7qh2: LangChain: RediSearch Filter Injection via Unescaped Tag/Text ValuesSame vendor · GitHub Advisory Database
- HighGHSA-fvww-7h3r-vfhp: LangGraph SDK custom auth silently ignores actions= on resource decoratorsSame vendor · GitHub Advisory Database
- HighCVE-2026-72848: SitemapLoader nested sitemap entries bypass restrict_to_same_domainSame vendor · NVD/CVE Database
- HighGHSA-533j-2v4q-mw5h: LangChain MongoDB has NoSQL Operator Injection in MongoDBSaver.list() leading to cross-tenant data exposureSame vendor · GitHub Advisory Database