Skip to content
MediumVulnerabilityLLM-specific

CVE-2026-108574: BerriAI LiteLLM authorization bypass in session spend log view via session_id

Identifier
CVE-2026-108574
Published
Record updated
View JSON
Known exploitation
Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.

Summary

A flaw in BerriAI LiteLLM up to 1.95.0 lies in the function ui_view_session_spend_logs in litellm/proxy/spend_tracking/spend_management_endpoints.py, part of the Spend Tracking component. Manipulating the session_id argument leads to authorization bypass, and the attack can be launched remotely. A published exploit exists.

Mitigation

Upgrade to version 1.96.0, which resolves the issue. The patch is identified as 722d9ffa4f6c5ae15702ab9ab2c5f6bf1688308b.