Skip to content
LowVulnerabilityLLM-specific

GHSA-m2v5-74w2-qhcj: BerriAI litellm: UI User Enumeration leads to System-Wide Information Disclosure

Published
Record updated
View JSON
Affected
  • litellm <= 1.82.2
Fixed in
No fixed version was stated when the source was last read.
Known exploitation
Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
EPSS
0.4%

Summary

A vulnerability in BerriAI litellm up to 1.82.2 lies in the ui_view_users function of litellm/proxy/management_endpoints/internal_user_endpoints.py, tracked as an incomplete fix for CVE-2025-0628. The flaw is an improper authorization issue that can be triggered remotely. The exploit has been publicly disclosed and may be used, and the vendor was contacted early about the disclosure.

Mitigation

The source does not state a fix yet. Check the original advisory for updates.