CVE-2026-12798: BerriAI litellm MCP OpenAPI Spec Loader openapi_to_mcp_generator.py load_openapi_spec_async server-side request forgery
A weakness has been identified in BerriAI litellm up to 1.82.2. Affected by this vulnerability is the function loadopenapispecasync of the file litellm/proxy/experimental/mcpserver/openapitomcpgenerator.py of the component MCP OpenAPI Spec Loader. This manipulation of the argument specpath causes server-side request forgery. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-12798?
CVE-2026-12798 has a medium severity rating of 6.3.
What type of vulnerability is CVE-2026-12798?
CVE-2026-12798 is classified as a server-side request forgery (SSRF) vulnerability.
How do I fix CVE-2026-12798?
To fix CVE-2026-12798, update the BerriAI litellm software to version 1.82.3 or later.
Which component is affected by CVE-2026-12798?
CVE-2026-12798 affects the MCP OpenAPI Spec Loader component in the BerriAI litellm software.
What function is exploited in CVE-2026-12798?
The vulnerability is exploited in the function load_openapi_spec_async located in openapi_to_mcp_generator.py.