MediumVulnerabilityLLM-specific
CVE-2026-108574: BerriAI LiteLLM authorization bypass in session spend log view via session_id
- Source
- NVD(opens in a new tab)
- Identifier
- CVE-2026-108574
- Published
- Record updated
- Known exploitation
- Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
Summary
A flaw in BerriAI LiteLLM up to 1.95.0 lies in the function ui_view_session_spend_logs in litellm/proxy/spend_tracking/spend_management_endpoints.py, part of the Spend Tracking component. Manipulating the session_id argument leads to authorization bypass, and the attack can be launched remotely. A published exploit exists.
Mitigation
Upgrade to version 1.96.0, which resolves the issue. The patch is identified as 722d9ffa4f6c5ae15702ab9ab2c5f6bf1688308b.
Related items
- MediumCVE-2026-108575: BerriAI LiteLLM improper authorization in secret resolution via api_keySimilar attack · NVD/CVE Database
- MediumCVE-2026-108670: JeecgBoot missing authorization in AiragPromptsControllerSimilar attack · NVD/CVE Database
- MediumCVE-2026-108600: open-multi-agent link following flaw in file_write tool sandboxSimilar attack · NVD/CVE Database
- MediumCVE-2026-108599: phi symlink escape in permission gate allows writes outside workspaceSimilar attack · NVD/CVE Database
- MediumCVE-2026-108597: Cohere Python SDK path traversal in model archive extractionSimilar attack · NVD/CVE Database