Executive brief
BerriAI litellm is an LLM proxy platform that orchestrates language model APIs. The MCP (Model Context Protocol) OpenAPI Spec Loader component fetches remote API specifications to dynamically load tool definitions. Due to missing URL validation, any authenticated user can trick the proxy into making HTTP requests to arbitrary internal URLs—including cloud metadata services—to steal AWS/GCP credentials, discover internal services, or perform port scanning. This bypasses network isolation and can lead to full infrastructure compromise.
Technical details
The vulnerability exists in the load_openapi_spec_async() function in litellm/proxy/_experimental/mcp_server/openapi_to_mcp_generator.py, which was recently enhanced to support remote HTTP/HTTPS URLs. The function accepts a user-controlled spec_path parameter and directly passes it to httpx.get() without URL validation, DNS rebinding protection, private IP filtering, or metadata endpoint blocking. The function is called from the /mcp-rest/test/tools/list REST endpoint, which is accessible to any authenticated user (not admin-only). An attacker with a valid API key can POST a crafted spec_path (e.g., http://169.254.169.254/latest/meta-data/) to exfiltrate cloud credentials, reach internal services (10.0.0.0/8, 192.168.0.0/16), or probe internal network topology. The PoC confirms successful extraction of internal service responses and port detection. No official patch has been released as of the advisory date.
Affected products
- BerriAI litellm <= 1.82.2
Timeline
- 2026-06-21: disclosed: Vulnerability disclosed to GitHub Advisory Database and NVD
- 2026-03-21: other: PoC and detailed technical report published by researcher YLChen-007
- 2026-09-14: other: GitHub advisory reviewed and updated