Skip to content
MediumVulnerability

GHSA-qqcv-vg9f-5rr3: litellm vulnerable to improper access control in team management

Published
Record updated
View JSON
Affected
  • litellm < 1.40.15
Fixed in
1.40.15
Known exploitation
Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
EPSS
0.4%

Summary

berriai/litellm version 1.34.34 has an improper access control flaw in its team management functionality. Insufficient access control checks in various team management endpoints let attackers create, update, view, delete, block, and unblock any team, and add or remove any team member, without authorization.

Mitigation

The source does not state a fix yet. Check the original advisory for updates.

Affected packages in the Exposure Registry

Matched by package name and ecosystem. Each entry shows whether the package delegates to a language model and how many tracked packages depend on it.

  • litellmPyPILLM dependency since 2023-07-27 · 54 tracked dependents