Skip to content
MediumVulnerabilityLLM-specific

GHSA-j37q-q7p9-vpwm: LiteLLM: SSO Debug Flow Has Improper Authentication

Published
Record updated
View JSON
Affected
  • litellm <= 1.82.2
Fixed in
No fixed version was stated when the source was last read.
Known exploitation
Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
EPSS
0.8%

Summary

A vulnerability in BerriAI litellm up to version 1.82.2 affects the json.dumps function in litellm/proxy/management_endpoints/ui_sso.py, part of the SSO Debug Flow component. Manipulating this component can lead to missing authentication, and the attack can be executed remotely. The exploit has been publicly disclosed and may be used, and the vendor was contacted early about the disclosure.

Mitigation

The source does not state a fix yet. Check the original advisory for updates.