Skip to content
MediumVulnerabilityLLM-specific

CVE-2026-108575: BerriAI LiteLLM improper authorization in secret resolution via api_key

Identifier
CVE-2026-108575
Published
Record updated
View JSON
Known exploitation
Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.

Summary

A vulnerability has been found in BerriAI LiteLLM up to 1.94.0, in the get_secret function of secret_managers/main.py within the Secret Resolution component. Manipulating the api_key argument leads to improper authorization, and the attack can be initiated remotely. The exploit is public and may be used, and the vendor did not respond after early contact.

Mitigation

The source does not state a fix yet. Check the original advisory for updates.