Skip to content
HighVulnerabilityLLM-specific

GHSA-fjcf-3j3r-78rp: LiteLLM Has an Improper Authorization Vulnerability

Published
Record updated
View JSON
Affected
  • litellm < 1.61.15
Fixed in
1.61.15
Known exploitation
Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
EPSS
0.3%

Summary

An improper authorization flaw in the main-latest version of BerriAI/litellm gives a user with the role 'internal_user_viewer' an overly privileged API key when they log in. That key reaches admin functionality, including endpoints such as '/users/list' and '/users/get_users'. The result is privilege escalation that lets any account become a PROXY ADMIN.

Mitigation

The source does not state a fix yet. Check the original advisory for updates.