MediumVulnerabilityLLM-specific
GHSA-4jcj-7x88-m979: LiteLLM: MCP Proxy Has Improper Authentication
- Identifiers
- CVE-2026-12773GHSA-4jcj-7x88-m979
- Published
- Record updated
- Affected
- litellm < 1.84.0
- Fixed in
- 1.84.0
- Known exploitation
- Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
- EPSS
- 1.0%
Summary
A weakness in BerriAI litellm up to 1.59.8 affects the function UserAPIKeyAuth in litellm/proxy/_experimental/mcp_server/auth/user_api_key_auth_mcp.py, part of the MCP Proxy component. Manipulating this component can lead to improper authentication, and the attack can be launched remotely. A public exploit exists, and the vendor was contacted early about the disclosure.
Mitigation
The source does not state a fix yet. Check the original advisory for updates.
Affected packages in the Exposure Registry
Matched by package name and ecosystem. Each entry shows whether the package delegates to a language model and how many tracked packages depend on it.
- litellmPyPILLM dependency since 2023-07-27 · 54 tracked dependents
Topics
Related items
- LowAnthropic Cuts Live Internet Access for Internal AI Tests After Claude Exploits Injection FlawsSimilar attack · The Hacker News
- CriticalCVE-2026-108263: Astron Agent code-node execution as root through workflow run endpointsSimilar attack · NVD/CVE Database
- MediumHackers abuse Google Ads, Bing redirects to push Claude ClickFix attacksSimilar attack · BleepingComputer
- CriticalHermes Agent - PKCE Session Takeover via Redirect-URI Parser ConfusionSimilar attack · Tenable Research Advisories
- LowSocial Engineering AI Agents: The New BEC for 2026Similar attack · Dark Reading