Where
-Infinity
0

LiteLLM LiteLLMCommand Injection

Risk 86
Severity
9.8
First published (updated )

LiteLLM LiteLLMLiteLLM: Local file read via request-supplied OIDC file references

Risk 30
Severity
2.1
First published (updated )

LiteLLMLiteLLM: MCP Authentication Bypass via OAuth2 Passthrough Fallback

Risk 57
Severity
8.8
First published (updated )

LiteLLM LiteLLMLiteLLM: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Risk 38
Severity
6.1
First published (updated )

LiteLLM LiteLLMLiteLLM: Custom Code Guardrails production endpoints bypass code safety checks

Risk 66
Severity
2.1
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

PSA: Critical LiteLLM AI Gateway RCE (CVE-2026-42271) added to CISA KEV. A technical breakdown of the exploit chain.

First published (updated )
Social
reddit

pypi/litellmBerriAI litellm Incomplete Fix CVE-2025-0628 internal_user_endpoints.py ui_view_users improper authorization

Risk 22
Severity
2.1
First published (updated )

pypi/litellmBerriAI litellm MCP OpenAPI Spec Loader openapi_to_mcp_generator.py load_openapi_spec_async server-side request forgery

Risk 46
Severity
2.1
First published (updated )

pypi/litellmBerriAI litellm Completions banned_keywords.py async_pre_call_hook authorization

Risk 46
Severity
2.1
First published (updated )

pypi/litellmBerriAI litellm SSO Authentication Flow ui_sso.py get_redirect_response_from_openid session expiration

Risk 46
Severity
2.1
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

pypi/litellmBerriAI litellm SSO Debug Flow ui_sso.py json.dumps missing authentication

Risk 52
Severity
5.5
First published (updated )

pypi/litellmBerriAI litellm MCP Server Connection Testing rest_endpoints.py _execute_with_mcp_client server-side request forgery

Risk 46
Severity
2.1
First published (updated )

pypi/litellmBerriAI litellm MCP Proxy user_api_key_auth_mcp.py UserAPIKeyAuth improper authentication

Risk 86
Severity
5.5
First published (updated )

BerriAI LiteLLMBerriAI litellm PROXY_ADMIN database API Key Generator login_utils.py authenticate_user session expiration

Risk 46
Severity
2.1
First published (updated )

pypi/litellmBerriAI litellm M2M JWT user_api_key_auth.py improper authorization

Risk 70
Severity
1.3
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

BerriAI LiteLLMBerriAI litellm Admin Key key_management_endpoints.py improper authorization

Risk 79
Severity
2.1
First published (updated )

pip/litellmLiteLLM: Authentication Bypass via Host Header Injection

Risk 86
Severity
9.5
First published (updated )

LiteLLM LiteLLMLiteLLM < 1.83.10 Privilege Escalation via User Update

Risk 79
Severity
8.7
First published (updated )

LiteLLM LiteLLMLiteLLM < 1.83.14 Privilege Escalation via API Key Generation

Risk 79
Severity
8.7
First published (updated )

LiteLLM LiteLLMLiteLLM: Server-Side Template Injection in /prompts/test endpoint

Risk 79
Severity
8.6
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

redhat OpenShift AIBerriAI LiteLLM Command Injection Vulnerability

Risk 95
Severity
8.7
First published (updated )

LiteLLM LiteLLMBerriAI LiteLLM SQL Injection Vulnerability

Risk 99
Severity
9.3
First published (updated )

LiteLLM LiteLLMLiteLLM through 2026-04-08 allows remote attackers to execute arbitrary code via bytecode rewriting …

Risk 33
Severity
7
First published (updated )

LiteLLM LiteLLMCode Injection

Risk 79
Severity
8.8
First published (updated )

oss-secX41 Advisory X41-2026-001: Guardrail Sandbox Escape in LiteLLM

First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

LiteLLM LiteLLMLiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.…

Risk 33
Severity
7
First published (updated )

LiteLLM LiteLLMLiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.…

Risk 33
Severity
7
First published (updated )

pip/litellmLiteLLM has an authentication bypass via OIDC userinfo cache key collision

Risk 64
Severity
9.4
First published (updated )

pip/litellmLiteLLM affected by privilege escalation via unrestricted proxy configuration endpoint

Risk 79
Severity
8.7
First published (updated )

LiteLLM LiteLLMAquasecurity Trivy Embedded Malicious Code Vulnerability

Risk 73
Severity
9.4
EPSS
0.07%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203