litellm
Library to easily interface with LLM API providers
Security Advisories for litellm in pypi
Moderate
9 days ago
LiteLLM Proxy has server-side request forgery via the `user_config` request parameter
pypi
litellm
Critical
29 days ago
LiteLLM vulnerable to server-side template injection in the /prompts/test endpoint
pypi
litellm
Low
2 months ago
LiteLLM: Custom Code Guardrails production endpoints bypass code safety checks
pypi
litellm
Moderate
2 months ago
LiteLLM: Arbitrary file write via path traversal in Skills archive extraction
pypi
litellm
Low
3 months ago
BerriAI litellm: UI User Enumeration leads to System-Wide Information Disclosure
pypi
litellm
Low
3 months ago
BerriAI litellm: SSO Login Does Not Invalidate Previous UI Session Tokens
pypi
litellm
Low
3 months ago
BerriAI litellm has SSRF via Unvalidated spec_path URL in MCP OpenAPI Spec Loader
pypi
litellm
Low
3 months ago
LiteLLM: PROXY_ADMIN database API Key Generator Has Insufficient Session Expiration
pypi
litellm
High
4 months ago
LiteLLM allows a user to modify their own user_role via the /user/update endpoint
pypi
litellm
High
4 months ago
LiteLLM allows an authenticated internal_user to create API keys with access to routes that their role does not permit
pypi
litellm
High
5 months ago
LiteLLM: Authenticated command execution via MCP stdio test endpoints
pypi
litellm
High
6 months ago
LiteLLM: Password hash exposure and pass-the-hash authentication bypass
pypi
litellm
Critical
6 months ago
LiteLLM: Authentication bypass via OIDC userinfo cache key collision
pypi
litellm
High
6 months ago
LiteLLM: Privilege escalation via unrestricted proxy configuration endpoint
pypi
litellm
Critical
6 months ago
Two LiteLLM versions published containing credential harvesting malware
pypi
litellm
High
over 1 year ago
LiteLLM Vulnerable to Denial of Service (DoS) via Crafted HTTP Request
pypi
litellm
Critical
about 2 years ago
litellm vulnerable to remote code execution based on using eval unsafely
pypi
litellm
Moderate
about 2 years ago
litellm vulnerable to improper access control in team management
pypi
litellm
High
over 2 years ago
litellm passes untrusted data to `eval` function without sanitization
pypi
litellm
Critical
over 2 years ago
LiteLLM has Server-Side Template Injection vulnerability in /completions endpoint
pypi
litellm