Skip to content
LowVulnerabilityLLM-specific

GHSA-6qr3-3g89-m4jj: LiteLLM: Admin Key Handler Has Improper Authorization

Published
Record updated
View JSON
Affected
  • litellm <= 1.63.1
Fixed in
No fixed version was stated when the source was last read.
Known exploitation
Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
EPSS
0.6%

Summary

A vulnerability in BerriAI litellm up to version 1.63.1 affects an unknown function in litellm/proxy/management_endpoints/key_management_endpoints.py, part of the Admin Key Handler component. It causes improper authorization and can be initiated remotely. The exploit has been publicly disclosed and may be used, and the vendor was contacted early about the disclosure.

Mitigation

The source does not state a fix yet. Check the original advisory for updates.