Executive brief
LiteLLM is an open-source proxy for managing LLM API access and user authentication. A flaw in its M2M JWT authentication handler allows a holder of a JWT token with admin scope to bypass intended route restrictions and access administrative management endpoints (user/team/key creation and deletion), granting full control over the proxy that should only be available through SSO-authenticated admin sessions. An attacker with a valid admin JWT can create users, teams, and API keys, potentially leading to unauthorized access and privilege escalation.
Technical details
The vulnerability exists in litellm/proxy/auth/user_api_key_auth.py where the JWT M2M authentication path (lines 673-852) lacks the route-guard protection that was previously applied to the OAuth2 M2M path. While OAuth2 M2M authentication correctly restricts token validation to LLM API routes and info routes via RouteChecks guards, the JWT authentication path applies to all routes without restriction. When a JWT token bearing the litellm_proxy_admin scope is presented, the auth handler returns a UserAPIKeyAuth object with PROXY_ADMIN role for any route, including protected management endpoints like /user/new, /team/new, /key/generate, and /key/delete. The attack requires a valid JWT token with admin scope from a configured JWKS endpoint, but requires only network access—no additional authentication or user interaction is needed beyond possessing the token. The vulnerability allows remote, unauthenticated M2M token holders to fully bypass UI SSO separation and gain administrative control over the proxy.
Affected products
- BerriAI LiteLLM <= 1.82.2
Timeline
- 2026-06-21: disclosed
- 2026-06-21: advisory: GitHub Security Advisory published
- 2026-09-10: other: GitHub reviewed and confirmed