{"schema_version":1,"title":"litellm (PyPI) vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 29 vulnerabilities in litellm (PyPI): 0 in the last 7 days and 17 in the last 90 days, 7 of them critical and 3 exploited in the wild. The most recent, CVE-2026-37004, was published on 27 August 2026.","url":"https://junglewise.ai/threats/technologies/pypi-litellm","json_url":"https://junglewise.ai/threats/technologies/pypi-litellm.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/pypi-litellm","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":5,"all_time":29,"critical":7,"exploited":3,"last_7_days":0,"last_30_days":0,"last_90_days":17,"last_365_days":28},"latest":[{"cve":"CVE-2026-37004","cvss":9.8,"epss":0.008,"slug":"cve-2026-37004-berriai-litellm-server-side-template-injection-in-prompts","title":"BerriAI litellm <=1.82.4 is vulnerable to Server-Side Template Injection (SSTI), which allows unauthenticated remote attackers to execute ar","severity":"critical","exploited":false,"published_at":"2026-08-27T20:17:41.27+00:00","url":"https://junglewise.ai/threats/cve-2026-37004-berriai-litellm-server-side-template-injection-in-prompts"},{"cve":"CVE-2026-59822","cvss":4,"epss":0.0084,"slug":"cve-2026-59822-berriai-litellm-authentication-bypass-in-mcp-endpoint","title":"BerriAI LiteLLM authentication bypass in MCP endpoint","severity":"critical","exploited":true,"published_at":"2026-07-08T20:16:57.683+00:00","url":"https://junglewise.ai/threats/cve-2026-59822-berriai-litellm-authentication-bypass-in-mcp-endpoint"},{"cve":"CVE-2026-59821","cvss":4,"epss":0.009,"slug":"cve-2026-59821-berriai-litellm-code-injection-in-custom-code-guardrails","title":"BerriAI LiteLLM code injection in Custom Code Guardrails","severity":"medium","exploited":false,"published_at":"2026-07-08T20:16:57.547+00:00","url":"https://junglewise.ai/threats/cve-2026-59821-berriai-litellm-code-injection-in-custom-code-guardrails"},{"cve":"CVE-2026-59820","cvss":4,"epss":0.0059,"slug":"cve-2026-59820-berriai-litellm-path-traversal-in-skills-archive-extraction","title":"BerriAI LiteLLM path traversal in Skills archive extraction","severity":"medium","exploited":false,"published_at":"2026-07-08T20:16:57.413+00:00","url":"https://junglewise.ai/threats/cve-2026-59820-berriai-litellm-path-traversal-in-skills-archive-extraction"},{"cve":"CVE-2026-59819","cvss":4,"epss":0.0057,"slug":"cve-2026-59819-berriai-litellm-local-file-read-in-health-test-connection","title":"BerriAI LiteLLM local file read in health test_connection endpoint","severity":"medium","exploited":false,"published_at":"2026-07-08T20:16:57.277+00:00","url":"https://junglewise.ai/threats/cve-2026-59819-berriai-litellm-local-file-read-in-health-test-connection"},{"cve":"CVE-2025-0330","cvss":3,"epss":0.0056,"slug":"cve-2025-0330-litellm-has-a-leakage-of-langfuse-api-keys","title":"PYSEC-2026-1543 - LiteLLM Has a Leakage of Langfuse API Keys","severity":"low","exploited":false,"published_at":"2026-07-07T14:34:58.666687+00:00","url":"https://junglewise.ai/threats/cve-2025-0330-litellm-has-a-leakage-of-langfuse-api-keys"},{"cve":"CVE-2025-0628","cvss":3,"epss":0.0034,"slug":"cve-2025-0628-litellm-has-an-improper-authorization-vulnerability","title":"PYSEC-2026-1546 - LiteLLM Has an Improper Authorization Vulnerability","severity":"low","exploited":false,"published_at":"2026-07-07T14:34:58.39788+00:00","url":"https://junglewise.ai/threats/cve-2025-0628-litellm-has-an-improper-authorization-vulnerability"},{"cve":"CVE-2024-9606","cvss":3,"epss":0.0075,"slug":"cve-2024-9606-litellm-reveals-portion-of-api-key-via-a-logging-file","title":"PYSEC-2026-1548 - LiteLLM Reveals Portion of API Key via a Logging File","severity":"low","exploited":false,"published_at":"2026-07-07T14:34:57.987531+00:00","url":"https://junglewise.ai/threats/cve-2024-9606-litellm-reveals-portion-of-api-key-via-a-logging-file"},{"cve":"CVE-2024-8984","cvss":3,"epss":0.0084,"slug":"cve-2024-8984-litellm-vulnerable-to-denial-of-service-dos-via-crafted-http","title":"PYSEC-2026-1545 - LiteLLM Vulnerable to Denial of Service (DoS) via Crafted HTTP Request","severity":"low","exploited":false,"published_at":"2026-07-07T14:34:57.277763+00:00","url":"https://junglewise.ai/threats/cve-2024-8984-litellm-vulnerable-to-denial-of-service-dos-via-crafted-http"},{"cve":"CVE-2024-6825","cvss":3,"epss":0.0165,"slug":"cve-2024-6825-litellm-vulnerable-to-remote-code-execution-rce","title":"PYSEC-2026-1541 - LiteLLM Vulnerable to Remote Code Execution (RCE)","severity":"low","exploited":false,"published_at":"2026-07-07T14:34:54.86761+00:00","url":"https://junglewise.ai/threats/cve-2024-6825-litellm-vulnerable-to-remote-code-execution-rce"},{"cve":"CVE-2024-10188","cvss":3,"epss":0.0056,"slug":"cve-2024-10188-litellm-vulnerable-to-denial-of-service-dos","title":"PYSEC-2026-1549 - LiteLLM Vulnerable to Denial of Service (DoS)","severity":"low","exploited":false,"published_at":"2026-07-07T14:34:51.139299+00:00","url":"https://junglewise.ai/threats/cve-2024-10188-litellm-vulnerable-to-denial-of-service-dos"},{"cve":"CVE-2024-6587","cvss":3,"epss":0.3532,"slug":"cve-2024-6587-litellm-server-side-request-forgery-ssrf-vulnerability","title":"PYSEC-2026-1547 - LiteLLM Server-Side Request Forgery (SSRF) vulnerability","severity":"low","exploited":false,"published_at":"2026-07-07T14:34:40.863022+00:00","url":"https://junglewise.ai/threats/cve-2024-6587-litellm-server-side-request-forgery-ssrf-vulnerability"},{"cve":"CVE-2024-5710","cvss":3.1,"epss":0.0041,"slug":"cve-2024-5710-litellm-vulnerable-to-improper-access-control-in-team-management","title":"PYSEC-2026-1551 - litellm vulnerable to improper access control in team management","severity":"low","exploited":false,"published_at":"2026-07-07T14:34:35.921148+00:00","url":"https://junglewise.ai/threats/cve-2024-5710-litellm-vulnerable-to-improper-access-control-in-team-management"},{"cve":"CVE-2024-5225","cvss":3,"epss":0.0043,"slug":"cve-2024-5225-sql-injection-in-litellm","title":"PYSEC-2026-1550 - SQL injection in litellm","severity":"low","exploited":false,"published_at":"2026-07-07T14:34:34.436601+00:00","url":"https://junglewise.ai/threats/cve-2024-5225-sql-injection-in-litellm"},{"cve":"CVE-2024-4890","cvss":3,"epss":0.0056,"slug":"cve-2024-4890-sql-injection-in-litellm","title":"PYSEC-2026-1544 - SQL injection in litellm","severity":"low","exploited":false,"published_at":"2026-07-07T14:34:34.255023+00:00","url":"https://junglewise.ai/threats/cve-2024-4890-sql-injection-in-litellm"},{"cve":"CVE-2024-4888","cvss":3,"epss":0.0062,"slug":"cve-2024-4888-arbitrary-file-deletion-in-litellm","title":"PYSEC-2026-1540 - Arbitrary file deletion in litellm","severity":"low","exploited":false,"published_at":"2026-07-07T14:34:34.023334+00:00","url":"https://junglewise.ai/threats/cve-2024-4888-arbitrary-file-deletion-in-litellm"},{"cve":"CVE-2024-4264","cvss":3.1,"epss":0.0088,"slug":"cve-2024-4264-litellm-passes-untrusted-data-to-eval-function-without","title":"PYSEC-2026-1542 - litellm passes untrusted data to `eval` function without sanitization","severity":"low","exploited":false,"published_at":"2026-07-07T11:45:42.739863+00:00","url":"https://junglewise.ai/threats/cve-2024-4264-litellm-passes-untrusted-data-to-eval-function-without"},{"cve":"CVE-2024-5751","cvss":3,"epss":0.0088,"slug":"cve-2024-5751-litellm-vulnerable-to-remote-code-execution-based-on-using-eval","title":"PYSEC-2026-389 - litellm vulnerable to remote code execution based on using eval unsafely","severity":"low","exploited":false,"published_at":"2026-06-29T11:50:41.762215+00:00","url":"https://junglewise.ai/threats/cve-2024-5751-litellm-vulnerable-to-remote-code-execution-based-on-using-eval"},{"cve":"CVE-2026-49468","cvss":4,"epss":0.0082,"slug":"cve-2026-49468-berriai-litellm-authentication-bypass-via-host-header-injection","title":"BerriAI LiteLLM authentication bypass via Host header injection","severity":"critical","exploited":false,"published_at":"2026-06-22T21:16:25.19+00:00","url":"https://junglewise.ai/threats/cve-2026-49468-berriai-litellm-authentication-bypass-via-host-header-injection"},{"cve":"CVE-2026-47102","cvss":8.8,"epss":0.0082,"slug":"cve-2026-47102-berriai-litellm-privilege-escalation-in-user-update-endpoint","title":"BerriAI LiteLLM privilege escalation in user update endpoint","severity":"high","exploited":false,"published_at":"2026-05-21T21:16:32.557+00:00","url":"https://junglewise.ai/threats/cve-2026-47102-berriai-litellm-privilege-escalation-in-user-update-endpoint"},{"cve":"CVE-2026-47101","cvss":8.8,"epss":0.0133,"slug":"cve-2026-47101-berriai-litellm-privilege-escalation-in-api-key-generation","title":"BerriAI LiteLLM privilege escalation in API key generation","severity":"high","exploited":false,"published_at":"2026-05-21T21:16:32.413+00:00","url":"https://junglewise.ai/threats/cve-2026-47101-berriai-litellm-privilege-escalation-in-api-key-generation"},{"cve":"CVE-2026-42271","cvss":8.8,"epss":0.1275,"slug":"cve-2026-42271-berriai-litellm-os-command-injection-in-mcp-test-endpoints","title":"BerriAI LiteLLM OS command injection in MCP test endpoints","severity":"critical","exploited":true,"published_at":"2026-05-08T04:16:21.82+00:00","url":"https://junglewise.ai/threats/cve-2026-42271-berriai-litellm-os-command-injection-in-mcp-test-endpoints"},{"cve":"CVE-2026-42208","cvss":9.8,"epss":0.0577,"slug":"cve-2026-42208-berriai-litellm-sql-injection-in-proxy-api-key-verification","title":"BerriAI LiteLLM SQL injection in Proxy API key verification","severity":"critical","exploited":true,"published_at":"2026-05-08T04:16:19.923+00:00","url":"https://junglewise.ai/threats/cve-2026-42208-berriai-litellm-sql-injection-in-proxy-api-key-verification"},{"cve":"CVE-2026-42203","cvss":8.8,"epss":0.0066,"slug":"cve-2026-42203-berriai-litellm-code-injection-in-prompts-test-endpoint","title":"BerriAI LiteLLM code injection in /prompts/test endpoint","severity":"high","exploited":false,"published_at":"2026-05-08T04:16:19.45+00:00","url":"https://junglewise.ai/threats/cve-2026-42203-berriai-litellm-code-injection-in-prompts-test-endpoint"},{"cve":"CVE-2026-40217","cvss":8.8,"epss":0.034,"slug":"cve-2026-40217-berriai-litellm-remote-code-execution-in-guardrails-component","title":"BerriAI LiteLLM remote code execution in guardrails component","severity":"high","exploited":false,"published_at":"2026-04-10T14:16:36.307+00:00","url":"https://junglewise.ai/threats/cve-2026-40217-berriai-litellm-remote-code-execution-in-guardrails-component"}],"weekly":[{"week":"2026-07-06","critical":1,"exploited":1,"vulnerabilities":16},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":1,"exploited":0,"vulnerabilities":1},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-28","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"tensorflow (PyPI)","slug":"pypi-tensorflow","vulnerabilities":428,"url":"https://junglewise.ai/threats/technologies/pypi-tensorflow"},{"name":"tensorflow-cpu (PyPI)","slug":"tensorflow-cpu","vulnerabilities":424,"url":"https://junglewise.ai/threats/technologies/tensorflow-cpu"},{"name":"tensorflow-gpu (PyPI)","slug":"tensorflow-gpu","vulnerabilities":421,"url":"https://junglewise.ai/threats/technologies/tensorflow-gpu"},{"name":"open-webui (PyPI)","slug":"open-webui","vulnerabilities":177,"url":"https://junglewise.ai/threats/technologies/open-webui"},{"name":"Django (PyPI)","slug":"django","vulnerabilities":172,"url":"https://junglewise.ai/threats/technologies/django"},{"name":"apache-airflow (PyPI)","slug":"apache-airflow","vulnerabilities":152,"url":"https://junglewise.ai/threats/technologies/apache-airflow"},{"name":"plone (PyPI)","slug":"pypi-plone","vulnerabilities":101,"url":"https://junglewise.ai/threats/technologies/pypi-plone"},{"name":"praisonai (PyPI)","slug":"pypi-praisonai","vulnerabilities":86,"url":"https://junglewise.ai/threats/technologies/pypi-praisonai"},{"name":"exiv2 (PyPI)","slug":"exiv2","vulnerabilities":85,"url":"https://junglewise.ai/threats/technologies/exiv2"},{"name":"nltk (PyPI)","slug":"nltk","vulnerabilities":83,"url":"https://junglewise.ai/threats/technologies/nltk"},{"name":"mlflow (PyPI)","slug":"mlflow","vulnerabilities":82,"url":"https://junglewise.ai/threats/technologies/mlflow"},{"name":"pillow (PyPI)","slug":"pillow","vulnerabilities":79,"url":"https://junglewise.ai/threats/technologies/pillow"}],"technology":{"hub":true,"name":"litellm (PyPI)","slug":"pypi-litellm","vendor":{"name":"PyPI","slug":"pypi","url":"https://junglewise.ai/threats/vendors/pypi"},"aliases":[],"repo_url":"https://github.com/BerriAI/litellm","description":"Large language model API abstraction layer supporting multiple model providers through unified interface.","url":"https://junglewise.ai/threats/technologies/pypi-litellm"},"most_severe":[{"cve":"CVE-2026-42208","cvss":9.8,"epss":0.0577,"slug":"cve-2026-42208-berriai-litellm-sql-injection-in-proxy-api-key-verification","title":"BerriAI LiteLLM SQL injection in Proxy API key verification","severity":"critical","exploited":true,"published_at":"2026-05-08T04:16:19.923+00:00","url":"https://junglewise.ai/threats/cve-2026-42208-berriai-litellm-sql-injection-in-proxy-api-key-verification"},{"cve":"CVE-2026-42271","cvss":8.8,"epss":0.1275,"slug":"cve-2026-42271-berriai-litellm-os-command-injection-in-mcp-test-endpoints","title":"BerriAI LiteLLM OS command injection in MCP test endpoints","severity":"critical","exploited":true,"published_at":"2026-05-08T04:16:21.82+00:00","url":"https://junglewise.ai/threats/cve-2026-42271-berriai-litellm-os-command-injection-in-mcp-test-endpoints"},{"cve":"CVE-2026-59822","cvss":4,"epss":0.0084,"slug":"cve-2026-59822-berriai-litellm-authentication-bypass-in-mcp-endpoint","title":"BerriAI LiteLLM authentication bypass in MCP endpoint","severity":"critical","exploited":true,"published_at":"2026-07-08T20:16:57.683+00:00","url":"https://junglewise.ai/threats/cve-2026-59822-berriai-litellm-authentication-bypass-in-mcp-endpoint"},{"cve":"CVE-2024-2952","cvss":9.8,"epss":0.0127,"slug":"cve-2024-2952-berriai-litellm-ssti-in-completions-endpoint","title":"BerriAI LiteLLM SSTI in completions endpoint","severity":"critical","exploited":false,"published_at":"2024-04-10T18:30:48+00:00","url":"https://junglewise.ai/threats/cve-2024-2952-berriai-litellm-ssti-in-completions-endpoint"},{"cve":"CVE-2026-37004","cvss":9.8,"epss":0.008,"slug":"cve-2026-37004-berriai-litellm-server-side-template-injection-in-prompts","title":"BerriAI litellm <=1.82.4 is vulnerable to Server-Side Template Injection (SSTI), which allows unauthenticated remote attackers to execute ar","severity":"critical","exploited":false,"published_at":"2026-08-27T20:17:41.27+00:00","url":"https://junglewise.ai/threats/cve-2026-37004-berriai-litellm-server-side-template-injection-in-prompts"},{"cve":"CVE-2026-35030","cvss":9.1,"epss":0.0088,"slug":"cve-2026-35030-berriai-litellm-authentication-bypass-via-oidc-cache-key","title":"BerriAI LiteLLM authentication bypass via OIDC cache key collision","severity":"critical","exploited":false,"published_at":"2026-04-06T17:17:12.65+00:00","url":"https://junglewise.ai/threats/cve-2026-35030-berriai-litellm-authentication-bypass-via-oidc-cache-key"},{"cve":"CVE-2026-49468","cvss":4,"epss":0.0082,"slug":"cve-2026-49468-berriai-litellm-authentication-bypass-via-host-header-injection","title":"BerriAI LiteLLM authentication bypass via Host header injection","severity":"critical","exploited":false,"published_at":"2026-06-22T21:16:25.19+00:00","url":"https://junglewise.ai/threats/cve-2026-49468-berriai-litellm-authentication-bypass-via-host-header-injection"},{"cve":"CVE-2026-35029","cvss":8.8,"epss":0.0398,"slug":"cve-2026-35029-berriai-litellm-incorrect-authorization-in-config-update-endpoint","title":"BerriAI LiteLLM incorrect authorization in config update endpoint","severity":"high","exploited":false,"published_at":"2026-04-06T17:17:12.353+00:00","url":"https://junglewise.ai/threats/cve-2026-35029-berriai-litellm-incorrect-authorization-in-config-update-endpoint"},{"cve":"CVE-2026-40217","cvss":8.8,"epss":0.034,"slug":"cve-2026-40217-berriai-litellm-remote-code-execution-in-guardrails-component","title":"BerriAI LiteLLM remote code execution in guardrails component","severity":"high","exploited":false,"published_at":"2026-04-10T14:16:36.307+00:00","url":"https://junglewise.ai/threats/cve-2026-40217-berriai-litellm-remote-code-execution-in-guardrails-component"},{"cve":"CVE-2026-47101","cvss":8.8,"epss":0.0133,"slug":"cve-2026-47101-berriai-litellm-privilege-escalation-in-api-key-generation","title":"BerriAI LiteLLM privilege escalation in API key generation","severity":"high","exploited":false,"published_at":"2026-05-21T21:16:32.413+00:00","url":"https://junglewise.ai/threats/cve-2026-47101-berriai-litellm-privilege-escalation-in-api-key-generation"}],"generated_at":"2026-09-28T03:07:00.154823+00:00"}