Skip to content
LowVulnerabilityLLM-specific

GHSA-mf52-j94g-746m: LiteLLM: PROXY_ADMIN database API Key Generator Has Insufficient Session Expiration

Published
Record updated
View JSON
Affected
  • litellm <= 1.82.2
Fixed in
No fixed version was stated when the source was last read.
Known exploitation
Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
EPSS
0.4%

Summary

A flaw in BerriAI litellm up to 1.82.2 lies in the authenticate_user function of litellm/proxy/auth/login_utils.py, within the PROXY_ADMIN database API Key Generator component. Manipulating it results in session expiration, and the attack can be launched remotely. A public exploit exists, and the vendor was contacted early about the disclosure.

Mitigation

The source does not state a fix yet. Check the original advisory for updates.