Skip to content
LowVulnerability

GHSA-c693-x898-5g4h: BerriAI litellm has SSRF via Unvalidated spec_path URL in MCP OpenAPI Spec Loader

Published
Record updated
View JSON
Affected
  • litellm <= 1.82.2
Fixed in
No fixed version was stated when the source was last read.
Known exploitation
Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
EPSS
0.4%

Summary

A weakness in BerriAI litellm up to 1.82.2 lies in the load_openapi_spec_async function of litellm/proxy/_experimental/mcp_server/openapi_to_mcp_generator.py, within the MCP OpenAPI Spec Loader component. Manipulating the spec_path argument causes server-side request forgery, and it can be exploited remotely. A public exploit exists, and the vendor was contacted early about the disclosure.

Mitigation

The source does not state a fix yet. Check the original advisory for updates.