Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-hx8v-g79f-8w5f
  • PyPI/litellm
LiteLLM Proxy has server-side request forgery via the `user_config` request parameter 3 days ago
  • Fix available
  • Severity - 5.3 (Medium)
PYSEC-2026-3861
  • PyPI/litellm
LiteLLM vulnerable to server-side template injection in the /prompts/test endpoint 10 Sep
  • Fix available
  • Severity - 9.8 (Critical)
GHSA-6wvf-77m9-58rm
  • PyPI/litellm
LiteLLM vulnerable to server-side template injection in the /prompts/test endpoint 27 Aug
  • Fix available
  • Severity - 9.8 (Critical)
PYSEC-2026-3478
  • PyPI/litellm
LiteLLM: Custom Code Guardrails production endpoints bypass code safety checks 23 Jul
  • Fix available
  • Severity - 2.1 (Low)
PYSEC-2026-3479
  • PyPI/litellm
LiteLLM: MCP Authentication Bypass via OAuth2 Passthrough Fallback 23 Jul
  • Fix available
  • Severity - 8.8 (High)
PYSEC-2026-3476
  • PyPI/litellm
LiteLLM: Local file read via request-supplied OIDC file references 23 Jul
  • Fix available
  • Severity - 2.1 (Low)
PYSEC-2026-3477
  • PyPI/litellm
LiteLLM: Arbitrary file write via path traversal in Skills archive extraction 23 Jul
  • Fix available
  • Severity - 6.1 (Medium)
GHSA-72m8-9m7m-h278
  • PyPI/litellm
LiteLLM: Custom Code Guardrails production endpoints bypass code safety checks 22 Jul
  • Fix available
  • Severity - 2.1 (Low)
GHSA-7488-6r32-c95q
  • PyPI/litellm
LiteLLM: MCP Authentication Bypass via OAuth2 Passthrough Fallback 22 Jul
  • Fix available
  • Severity - 8.8 (High)
GHSA-4g5m-c9r5-49xf
  • PyPI/litellm
LiteLLM: Local file read via request-supplied OIDC file references 22 Jul
  • Fix available
  • Severity - 2.1 (Low)
GHSA-5jmr-gcrj-2c9q
  • PyPI/litellm
LiteLLM: Arbitrary file write via path traversal in Skills archive extraction 22 Jul
  • Fix available
  • Severity - 6.1 (Medium)
PYSEC-2026-2600
  • PyPI/litellm
LiteLLM allows a user to modify their own user_role via the /user/update endpoint 13 Jul
  • Fix available
  • Severity - 8.7 (High)
PYSEC-2026-2598
  • PyPI/litellm
LiteLLM allows an authenticated internal_user to create API keys with access to routes that their role does not permit 13 Jul
  • Fix available
  • Severity - 8.7 (High)
PYSEC-2026-2601
  • PyPI/litellm
LiteLLM has a sandbox escape in custom-code guardrail 13 Jul
  • Fix available
  • Severity - 7.5 (High)
PYSEC-2026-2599
  • PyPI/litellm
LiteLLM: Authenticated command execution via MCP stdio test endpoints 13 Jul
  • Fix available
  • Severity - 8.7 (High)
PYSEC-2026-2602
  • PyPI/litellm
LiteLLM: Server-Side Template Injection in /prompts/test endpoint 13 Jul
  • Fix available
  • Severity - 8.6 (High)