CVE-2026-108575: BerriAI LiteLLM Secret Resolution main.py get_secret improper authorization
A vulnerability has been found in BerriAI LiteLLM up to 1.94.0. This affects the function getsecret of the file secretmanagers/main.py of the component Secret Resolution. The manipulation of the argument apikey leads to improper authorization. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
Which deployments are affected?
BerriAI LiteLLM deployments running versions up to and including 1.94.0 are affected where the Secret Resolution component uses the get_secret function in secret_managers/main.py.
What does an attacker need to exploit this issue?
The attack can be initiated remotely and requires low privileges. Exploitation involves manipulating the api_key argument supplied to get_secret; no user interaction is required.
Is public exploit information available?
Yes. The exploit has been publicly disclosed and may be used.
Is a vendor fix or response identified in the available information?
No vendor response is identified. The vendor was contacted early about the disclosure but did not respond, and the provided data does not identify a fixed version or workaround.