Technology · PyPI
litellm (PyPI) vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 29 vulnerabilities in litellm (PyPI): 0 in the last 7 days and 17 in the last 90 days, 7 of them critical and 3 exploited in the wild. The most recent, CVE-2026-37004, was published on 27 August 2026.
- Last 7 days
- 0
- Last 90 days
- 17
- Critical, all time
- 7
- Exploited in the wild
- 3
About litellm (PyPI)
Large language model API abstraction layer supporting multiple model providers through unified interface.
Latest litellm (PyPI) vulnerabilities
- CVE-2026-37004: BerriAI litellm <=1.82.4 is vulnerable to Server-Side Template Injection (SSTI), which allows unauthenticated remote…criticalCVSS 9.8EPSS 0.8%
- CVE-2026-59822: BerriAI LiteLLM authentication bypass in MCP endpointcriticalexploited in the wildCVSS 4EPSS 0.8%
- CVE-2026-59821: BerriAI LiteLLM code injection in Custom Code GuardrailsmediumCVSS 4EPSS 0.9%
- CVE-2026-59820: BerriAI LiteLLM path traversal in Skills archive extractionmediumCVSS 4EPSS 0.6%
- CVE-2026-59819: BerriAI LiteLLM local file read in health test_connection endpointmediumCVSS 4EPSS 0.6%
- CVE-2025-0330: PYSEC-2026-1543 - LiteLLM Has a Leakage of Langfuse API KeyslowCVSS 3EPSS 0.6%
- CVE-2025-0628: PYSEC-2026-1546 - LiteLLM Has an Improper Authorization VulnerabilitylowCVSS 3EPSS 0.3%
- CVE-2024-9606: PYSEC-2026-1548 - LiteLLM Reveals Portion of API Key via a Logging FilelowCVSS 3EPSS 0.8%
- CVE-2024-8984: PYSEC-2026-1545 - LiteLLM Vulnerable to Denial of Service (DoS) via Crafted HTTP RequestlowCVSS 3EPSS 0.8%
- CVE-2024-6825: PYSEC-2026-1541 - LiteLLM Vulnerable to Remote Code Execution (RCE)lowCVSS 3EPSS 1.7%
- CVE-2024-10188: PYSEC-2026-1549 - LiteLLM Vulnerable to Denial of Service (DoS)lowCVSS 3EPSS 0.6%
- CVE-2024-6587: PYSEC-2026-1547 - LiteLLM Server-Side Request Forgery (SSRF) vulnerabilitylowCVSS 3EPSS 35.3%
- CVE-2024-5710: PYSEC-2026-1551 - litellm vulnerable to improper access control in team managementlowCVSS 3.1EPSS 0.4%
- CVE-2024-5225: PYSEC-2026-1550 - SQL injection in litellmlowCVSS 3EPSS 0.4%
- CVE-2024-4890: PYSEC-2026-1544 - SQL injection in litellmlowCVSS 3EPSS 0.6%
- CVE-2024-4888: PYSEC-2026-1540 - Arbitrary file deletion in litellmlowCVSS 3EPSS 0.6%
- CVE-2024-4264: PYSEC-2026-1542 - litellm passes untrusted data to `eval` function without sanitizationlowCVSS 3.1EPSS 0.9%
- CVE-2024-5751: PYSEC-2026-389 - litellm vulnerable to remote code execution based on using eval unsafelylowCVSS 3EPSS 0.9%
- CVE-2026-49468: BerriAI LiteLLM authentication bypass via Host header injectioncriticalCVSS 4EPSS 0.8%
- CVE-2026-47102: BerriAI LiteLLM privilege escalation in user update endpointhighCVSS 8.8EPSS 0.8%
- CVE-2026-47101: BerriAI LiteLLM privilege escalation in API key generationhighCVSS 8.8EPSS 1.3%
- CVE-2026-42271: BerriAI LiteLLM OS command injection in MCP test endpointscriticalexploited in the wildCVSS 8.8EPSS 12.8%
- CVE-2026-42208: BerriAI LiteLLM SQL injection in Proxy API key verificationcriticalexploited in the wildCVSS 9.8EPSS 5.8%
- CVE-2026-42203: BerriAI LiteLLM code injection in /prompts/test endpointhighCVSS 8.8EPSS 0.7%
- CVE-2026-40217: BerriAI LiteLLM remote code execution in guardrails componenthighCVSS 8.8EPSS 3.4%
Most severe litellm (PyPI) vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-42208: BerriAI LiteLLM SQL injection in Proxy API key verificationcriticalexploited in the wildCVSS 9.8EPSS 5.8%
- CVE-2026-42271: BerriAI LiteLLM OS command injection in MCP test endpointscriticalexploited in the wildCVSS 8.8EPSS 12.8%
- CVE-2026-59822: BerriAI LiteLLM authentication bypass in MCP endpointcriticalexploited in the wildCVSS 4EPSS 0.8%
- CVE-2024-2952: BerriAI LiteLLM SSTI in completions endpointcriticalCVSS 9.8EPSS 1.3%
- CVE-2026-37004: BerriAI litellm <=1.82.4 is vulnerable to Server-Side Template Injection (SSTI), which allows unauthenticated remote…criticalCVSS 9.8EPSS 0.8%
- CVE-2026-35030: BerriAI LiteLLM authentication bypass via OIDC cache key collisioncriticalCVSS 9.1EPSS 0.9%
- CVE-2026-49468: BerriAI LiteLLM authentication bypass via Host header injectioncriticalCVSS 4EPSS 0.8%
- CVE-2026-35029: BerriAI LiteLLM incorrect authorization in config update endpointhighCVSS 8.8EPSS 4.0%
- CVE-2026-40217: BerriAI LiteLLM remote code execution in guardrails componenthighCVSS 8.8EPSS 3.4%
- CVE-2026-47101: BerriAI LiteLLM privilege escalation in API key generationhighCVSS 8.8EPSS 1.3%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 6 Jul 2026 | 16 | 1 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 1 | 1 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 | |
| 28 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/pypi-litellm.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "litellm (PyPI) vulnerabilities", https://junglewise.ai/threats/technologies/pypi-litellm, 28 September 2026.