LiteLLM records
37 published records for vendor litellm.
Researcher profile
- Entered KEV
- 4 · 10.8%
- Weaponized
- 4 · 10.8%
- Pre-auth RCE
- 3
- With a fix record
- 62.2%
- Median publish → KEV
- 17 days
Recurring classes
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')4
- CWE-287 Improper Authentication4
- CWE-94 Improper Control of Generation of Code ('Code Injection')4
- CWE-918 Server-Side Request Forgery (SSRF)3
- CWE-266 Incorrect Privilege Assignment3
- CWE-863 Incorrect Authorization3
The weakness classes this vendor ships most often: where to look.
CWEAll records
37 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
92Now | CVE-2026-42271Weaponized | LiteLLM: Authenticated command execution via MCP stdio test endpointslitellm · litellm · CWE-77 | High8.7 | KEV | 92.6% | May 8, 2026 |
69This week | CVE-2026-42208Weaponized | LiteLLM: SQL injection in Proxy API key verificationlitellm · litellm · CWE-89 | Critical9.3 | KEV | 5.8% | May 8, 2026 |
68This week | CVE-2026-33634Weaponized | Trivy ecosystem supply chain briefly compromisedaquasec · setup-trivy · CWE-506 | Critical9.4 | KEV | 1.7% | Mar 23, 2026 |
65This week | CVE-2026-59822Weaponized | LiteLLM: MCP Authentication Bypass via OAuth2 Passthrough Fallbacklitellm · litellm · CWE-287 | High8.8 | KEV | 0.8% | Jul 8, 2026 |
41Plan | CVE-2024-6587Proof of concept | SSRF in berriai/litellmlitellm · litellm · CWE-918 | High7.5 | — | 35.3% | Sep 13, 2024 |
39Monitor | CVE-2024-2952No exploit | Server-Side Template Injection in BerriAI/litellmlitellm · litellm · CWE-76 | Critical9.8 | — | 1.3% | Apr 10, 2024 |
39Monitor | CVE-2024-5751No exploit | Remote Code Execution in BerriAI/litellmlitellm · litellm · CWE-94 | Critical9.8 | — | 0.9% | Jun 27, 2024 |
38Monitor | CVE-2026-49468Proof of concept | LiteLLM: Authentication Bypass via Host Header Injectionlitellm · litellm · CWE-290 | Critical9.5 | — | 0.8% | Jun 22, 2026 |
37Monitor | CVE-2026-35030Proof of concept | LiteLLM has an authentication bypass via OIDC userinfo cache key collisionlitellm · litellm · CWE-287 | Critical9.4 | — | 0.9% | Apr 6, 2026 |
36Monitor | CVE-2026-40217Proof of concept | LiteLLM through 2026-04-08 allows remote attackers to execute arbitrary code via bytecode rewriting at the /guardrails/test_custom_code URI.litellm · litellm · CWE-420 | High8.8 | — | 3.4% | Apr 10, 2026 |
35Monitor | CVE-2026-35029Proof of concept | LiteLLM affected by privilege escalation via unrestricted proxy configuration endpointlitellm · litellm · CWE-863 | High8.7 | — | 4.0% | Apr 6, 2026 |
35Monitor | CVE-2024-6825No exploit | Remote Code Execution in BerriAI/litellmlitellm · litellm · CWE-94 | High8.8 | — | 1.7% | Mar 20, 2025 |
34Monitor | CVE-2026-47101Proof of concept | LiteLLM < 1.83.14 Privilege Escalation via API Key Generationlitellm · litellm · CWE-863 | High8.7 | — | 1.3% | May 21, 2026 |
34Monitor | CVE-2026-47102Proof of concept | LiteLLM < 1.83.10 Privilege Escalation via User Updatelitellm · litellm · CWE-863 | High8.7 | — | 0.8% | May 21, 2026 |
34Monitor | CVE-2026-42203Proof of concept | LiteLLM: Server-Side Template Injection in /prompts/test endpointlitellm · litellm · CWE-1336 | High8.6 | — | 0.7% | May 8, 2026 |
32Monitor | CVE-2024-4888No exploit | Arbitrary File Deletion in BerriAI/litellmlitellm · litellm · CWE-862 | High8.1 | — | 0.6% | Jun 6, 2024 |
30Monitor | CVE-2024-8984No exploit | Denial of Service (DoS) in berriai/litellmlitellm · litellm · CWE-770 | High7.5 | — | 0.8% | Mar 20, 2025 |
30Monitor | CVE-2024-9606No exploit | Improper Output Neutralization for Logs in berriai/litellmlitellm · litellm · CWE-117 | High7.5 | — | 0.8% | Mar 20, 2025 |
30Monitor | CVE-2025-0330No exploit | Exposure of Sensitive Information in berriai/litellmlitellm · litellm · CWE-1230 | High7.5 | — | 0.6% | Mar 20, 2025 |
28Monitor | CVE-2024-4889No exploit | Code Injection in berriai/litellmlitellm · litellm · CWE-94 | High7.2 | — | 0.9% | Jun 6, 2024 |
28Monitor | CVE-2024-5225No exploit | SQL Injection in berriai/litellmlitellm · litellm · CWE-89 | High7.2 | — | 0.4% | Jun 6, 2024 |
26Monitor | CVE-2024-5710No exploit | Improper Access Control in Team Management in berriai/litellmlitellm · litellm · CWE-862 | Medium6.5 | — | 0.4% | Jun 27, 2024 |
24Monitor | CVE-2026-59820No exploit | LiteLLM: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')litellm · litellm · CWE-22 | Medium6.1 | — | 0.6% | Jul 8, 2026 |
22Monitor | CVE-2026-12773No exploit | BerriAI litellm MCP Proxy user_api_key_auth_mcp.py UserAPIKeyAuth improper authenticationlitellm · litellm · CWE-287 | Medium5.5 | — | 1.0% | Jun 21, 2026 |
22Monitor | CVE-2026-12795No exploit | BerriAI litellm SSO Debug Flow ui_sso.py json.dumps missing authenticationlitellm · litellm · CWE-287 | Medium5.5 | — | 0.8% | Jun 21, 2026 |
- CVE-2026-4227192Now
LiteLLM: Authenticated command execution via MCP stdio test endpoints
HighCVSS 8.7KEVWeaponizedEPSS 93%litellm · litellmMay 8, 2026
- CVE-2026-4220869This week
LiteLLM: SQL injection in Proxy API key verification
CriticalCVSS 9.3KEVWeaponizedEPSS 6%litellm · litellmMay 8, 2026
- CVE-2026-3363468This week
Trivy ecosystem supply chain briefly compromised
CriticalCVSS 9.4KEVWeaponizedEPSS 2%aquasec · setup-trivyMar 23, 2026
- CVE-2026-5982265This week
LiteLLM: MCP Authentication Bypass via OAuth2 Passthrough Fallback
HighCVSS 8.8KEVWeaponizedEPSS 1%litellm · litellmJul 8, 2026
- CVE-2024-658741Plan
SSRF in berriai/litellm
HighCVSS 7.5Proof of conceptEPSS 35%litellm · litellmSep 13, 2024
- CVE-2024-295239Monitor
Server-Side Template Injection in BerriAI/litellm
CriticalCVSS 9.8No exploitEPSS 1%litellm · litellmApr 10, 2024
- CVE-2024-575139Monitor
Remote Code Execution in BerriAI/litellm
CriticalCVSS 9.8No exploitEPSS 1%litellm · litellmJun 27, 2024
- CVE-2026-4946838Monitor
LiteLLM: Authentication Bypass via Host Header Injection
CriticalCVSS 9.5Proof of conceptEPSS 1%litellm · litellmJun 22, 2026
- CVE-2026-3503037Monitor
LiteLLM has an authentication bypass via OIDC userinfo cache key collision
CriticalCVSS 9.4Proof of conceptEPSS 1%litellm · litellmApr 6, 2026
- CVE-2026-4021736Monitor
LiteLLM through 2026-04-08 allows remote attackers to execute arbitrary code via bytecode rewriting at the /guardrails/test_custom_code URI.
HighCVSS 8.8Proof of conceptEPSS 3%litellm · litellmApr 10, 2026
- CVE-2026-3502935Monitor
LiteLLM affected by privilege escalation via unrestricted proxy configuration endpoint
HighCVSS 8.7Proof of conceptEPSS 4%litellm · litellmApr 6, 2026
- CVE-2024-682535Monitor
Remote Code Execution in BerriAI/litellm
HighCVSS 8.8No exploitEPSS 2%litellm · litellmMar 20, 2025
- CVE-2026-4710134Monitor
LiteLLM < 1.83.14 Privilege Escalation via API Key Generation
HighCVSS 8.7Proof of conceptEPSS 1%litellm · litellmMay 21, 2026
- CVE-2026-4710234Monitor
LiteLLM < 1.83.10 Privilege Escalation via User Update
HighCVSS 8.7Proof of conceptEPSS 1%litellm · litellmMay 21, 2026
- CVE-2026-4220334Monitor
LiteLLM: Server-Side Template Injection in /prompts/test endpoint
HighCVSS 8.6Proof of conceptEPSS 1%litellm · litellmMay 8, 2026
- CVE-2024-488832Monitor
Arbitrary File Deletion in BerriAI/litellm
HighCVSS 8.1No exploitEPSS 1%litellm · litellmJun 6, 2024
- CVE-2024-898430Monitor
Denial of Service (DoS) in berriai/litellm
HighCVSS 7.5No exploitEPSS 1%litellm · litellmMar 20, 2025
- CVE-2024-960630Monitor
Improper Output Neutralization for Logs in berriai/litellm
HighCVSS 7.5No exploitEPSS 1%litellm · litellmMar 20, 2025
- CVE-2025-033030Monitor
Exposure of Sensitive Information in berriai/litellm
HighCVSS 7.5No exploitEPSS 1%litellm · litellmMar 20, 2025
- CVE-2024-488928Monitor
Code Injection in berriai/litellm
HighCVSS 7.2No exploitEPSS 1%litellm · litellmJun 6, 2024
- CVE-2024-522528Monitor
SQL Injection in berriai/litellm
HighCVSS 7.2No exploitEPSS 0%litellm · litellmJun 6, 2024
- CVE-2024-571026Monitor
Improper Access Control in Team Management in berriai/litellm
MediumCVSS 6.5No exploitEPSS 0%litellm · litellmJun 27, 2024
- CVE-2026-5982024Monitor
LiteLLM: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
MediumCVSS 6.1No exploitEPSS 1%litellm · litellmJul 8, 2026
- CVE-2026-1277322Monitor
BerriAI litellm MCP Proxy user_api_key_auth_mcp.py UserAPIKeyAuth improper authentication
MediumCVSS 5.5No exploitEPSS 1%litellm · litellmJun 21, 2026
- CVE-2026-1279522Monitor
BerriAI litellm SSO Debug Flow ui_sso.py json.dumps missing authentication
MediumCVSS 5.5No exploitEPSS 1%litellm · litellmJun 21, 2026