Skip to content
LowVulnerabilityLLM-specific

GHSA-qmf3-4767-5fg3: LiteLLM: M2M JWT Handler Has Improper Authorization

Published
Record updated
View JSON
Affected
  • litellm <= 1.82.2
Fixed in
No fixed version was stated when the source was last read.
Known exploitation
Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
EPSS
0.4%

Summary

A vulnerability in BerriAI litellm up to 1.82.2 affects an unknown function in litellm/proxy/auth/user_api_key_auth.py, part of the M2M JWT Handler component. It leads to improper authorization and can be launched remotely, though the attack complexity is high and exploitability is reported as difficult. A public exploit is available and might be used, and the vendor was contacted early about the disclosure.

Mitigation

The source does not state a fix yet. Check the original advisory for updates.