{"schema_version":1,"title":"Berriai vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 31 vulnerabilities in Berriai: 1 in the last 7 days and 9 in the last 90 days, 7 of them critical and 3 exploited in the wild. The most recent, CVE-2026-89032, was published on 25 September 2026. 1 technology has a page of its own.","url":"https://junglewise.ai/threats/vendors/berriai","json_url":"https://junglewise.ai/threats/vendors/berriai.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/vendors/berriai","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"vendor","counts":{"high":9,"all_time":31,"critical":7,"exploited":3,"last_7_days":1,"last_30_days":4,"last_90_days":9,"last_365_days":30},"latest":[{"cve":"CVE-2026-89032","cvss":7.7,"slug":"cve-2026-89032-berriai-litellm-before-1-101-0-rc-1-contains-a-tenant-isolation","title":"BerriAI LiteLLM tenant isolation bypass in semantic cache","severity":"high","exploited":false,"published_at":"2026-09-25T17:17:18.793+00:00","url":"https://junglewise.ai/threats/cve-2026-89032-berriai-litellm-before-1-101-0-rc-1-contains-a-tenant-isolation"},{"cve":"CVE-2026-59823","cvss":4,"epss":0.0044,"slug":"cve-2026-59823-litellm-proxy-server-side-request-forgery-in-user-config","title":"LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.9, an authenticated LiteLLM Proxy caller","severity":"medium","exploited":false,"published_at":"2026-09-16T19:17:21.377+00:00","url":"https://junglewise.ai/threats/cve-2026-59823-litellm-proxy-server-side-request-forgery-in-user-config"},{"cve":"CVE-2026-84377","cvss":6.5,"epss":0.0054,"slug":"cve-2026-84377-litellm-proxy-request-parameter-injection-leading-to-credential","title":"LiteLLM proxy request parameter injection leading to credential exposure","severity":"medium","exploited":false,"published_at":"2026-09-02T18:21:28.997+00:00","url":"https://junglewise.ai/threats/cve-2026-84377-litellm-proxy-request-parameter-injection-leading-to-credential"},{"cve":"CVE-2026-37004","cvss":9.8,"epss":0.008,"slug":"cve-2026-37004-berriai-litellm-server-side-template-injection-in-prompts","title":"BerriAI litellm <=1.82.4 is vulnerable to Server-Side Template Injection (SSTI), which allows unauthenticated remote attackers to execute ar","severity":"critical","exploited":false,"published_at":"2026-08-27T20:17:41.27+00:00","url":"https://junglewise.ai/threats/cve-2026-37004-berriai-litellm-server-side-template-injection-in-prompts"},{"cve":"CVE-2026-30623","cvss":8.8,"slug":"cve-2026-30623-berriai-litellm-remote-code-execution-in-mcp-server-creation","title":"BerriAI LiteLLM remote code execution in MCP server creation","severity":"info","exploited":false,"published_at":"2026-07-15T22:16:46.317+00:00","url":"https://junglewise.ai/threats/cve-2026-30623-berriai-litellm-remote-code-execution-in-mcp-server-creation"},{"cve":"CVE-2026-59822","cvss":4,"epss":0.0084,"slug":"cve-2026-59822-berriai-litellm-authentication-bypass-in-mcp-endpoint","title":"BerriAI LiteLLM authentication bypass in MCP endpoint","severity":"critical","exploited":true,"published_at":"2026-07-08T20:16:57.683+00:00","url":"https://junglewise.ai/threats/cve-2026-59822-berriai-litellm-authentication-bypass-in-mcp-endpoint"},{"cve":"CVE-2026-59821","cvss":4,"epss":0.009,"slug":"cve-2026-59821-berriai-litellm-code-injection-in-custom-code-guardrails","title":"BerriAI LiteLLM code injection in Custom Code Guardrails","severity":"medium","exploited":false,"published_at":"2026-07-08T20:16:57.547+00:00","url":"https://junglewise.ai/threats/cve-2026-59821-berriai-litellm-code-injection-in-custom-code-guardrails"},{"cve":"CVE-2026-59820","cvss":4,"epss":0.0059,"slug":"cve-2026-59820-berriai-litellm-path-traversal-in-skills-archive-extraction","title":"BerriAI LiteLLM path traversal in Skills archive extraction","severity":"medium","exploited":false,"published_at":"2026-07-08T20:16:57.413+00:00","url":"https://junglewise.ai/threats/cve-2026-59820-berriai-litellm-path-traversal-in-skills-archive-extraction"},{"cve":"CVE-2026-59819","cvss":4,"epss":0.0057,"slug":"cve-2026-59819-berriai-litellm-local-file-read-in-health-test-connection","title":"BerriAI LiteLLM local file read in health test_connection endpoint","severity":"medium","exploited":false,"published_at":"2026-07-08T20:16:57.277+00:00","url":"https://junglewise.ai/threats/cve-2026-59819-berriai-litellm-local-file-read-in-health-test-connection"},{"cve":"CVE-2026-49468","cvss":3.1,"epss":0.0082,"slug":"cve-2026-49468-berriai-litellm-authentication-bypass-via-host-header-injection","title":"BerriAI LiteLLM authentication bypass via Host header injection","severity":"critical","exploited":false,"published_at":"2026-06-22T21:16:25.19+00:00","url":"https://junglewise.ai/threats/cve-2026-49468-berriai-litellm-authentication-bypass-via-host-header-injection"},{"cve":"CVE-2026-12799","cvss":4.3,"epss":0.0043,"slug":"cve-2026-12799-berriai-litellm-improper-authorization-in-ui-view-users-function","title":"BerriAI LiteLLM improper authorization in ui_view_users function","severity":"medium","exploited":false,"published_at":"2026-06-21T10:16:17.173+00:00","url":"https://junglewise.ai/threats/cve-2026-12799-berriai-litellm-improper-authorization-in-ui-view-users-function"},{"cve":"CVE-2026-12798","cvss":6.3,"epss":0.004,"slug":"cve-2026-12798-berriai-litellm-ssrf-in-mcp-openapi-spec-loader","title":"BerriAI litellm SSRF in MCP OpenAPI Spec Loader","severity":"medium","exploited":false,"published_at":"2026-06-21T10:16:17.023+00:00","url":"https://junglewise.ai/threats/cve-2026-12798-berriai-litellm-ssrf-in-mcp-openapi-spec-loader"},{"cve":"CVE-2026-12797","cvss":6.3,"epss":0.004,"slug":"cve-2026-12797-berriai-litellm-security-bypass-in-bannedkeywords-and","title":"BerriAI LiteLLM security bypass in BannedKeywords and AzureContentSafety hooks","severity":"medium","exploited":false,"published_at":"2026-06-21T10:16:16.87+00:00","url":"https://junglewise.ai/threats/cve-2026-12797-berriai-litellm-security-bypass-in-bannedkeywords-and"},{"cve":"CVE-2026-12796","cvss":6.3,"epss":0.0057,"slug":"cve-2026-12796-berriai-litellm-insufficient-session-expiration-in-sso-flow","title":"BerriAI LiteLLM insufficient session expiration in SSO flow","severity":"medium","exploited":false,"published_at":"2026-06-21T10:16:15.22+00:00","url":"https://junglewise.ai/threats/cve-2026-12796-berriai-litellm-insufficient-session-expiration-in-sso-flow"},{"cve":"CVE-2026-12795","cvss":7.3,"epss":0.008,"slug":"cve-2026-12795-berriai-litellm-missing-authentication-in-sso-debug-endpoints","title":"BerriAI LiteLLM missing authentication in SSO debug endpoints","severity":"high","exploited":false,"published_at":"2026-06-21T09:16:25.887+00:00","url":"https://junglewise.ai/threats/cve-2026-12795-berriai-litellm-missing-authentication-in-sso-debug-endpoints"},{"cve":"CVE-2026-12774","cvss":6.3,"slug":"cve-2026-12774-berriai-litellm-ssrf-in-mcp-server-connection-testing","title":"BerriAI LiteLLM SSRF in MCP Server Connection Testing","severity":"medium","exploited":false,"published_at":"2026-06-21T04:16:31.717+00:00","url":"https://junglewise.ai/threats/cve-2026-12774-berriai-litellm-ssrf-in-mcp-server-connection-testing"},{"cve":"CVE-2026-12773","cvss":7.3,"epss":0.0102,"slug":"cve-2026-12773-berriai-litellm-authentication-bypass-in-mcp-proxy","title":"BerriAI LiteLLM authentication bypass in MCP Proxy","severity":"high","exploited":false,"published_at":"2026-06-21T04:16:28.23+00:00","url":"https://junglewise.ai/threats/cve-2026-12773-berriai-litellm-authentication-bypass-in-mcp-proxy"},{"cve":"CVE-2026-12772","cvss":6.3,"epss":0.004,"slug":"cve-2026-12772-berriai-litellm-insufficient-session-expiration-in-admin-ui-login","title":"BerriAI LiteLLM insufficient session expiration in Admin UI login","severity":"medium","exploited":false,"published_at":"2026-06-21T03:16:22.96+00:00","url":"https://junglewise.ai/threats/cve-2026-12772-berriai-litellm-insufficient-session-expiration-in-admin-ui-login"},{"cve":"CVE-2026-12771","cvss":5,"epss":0.0043,"slug":"cve-2026-12771-berriai-litellm-improper-authorization-in-m2m-jwt-handler","title":"BerriAI LiteLLM improper authorization in M2M JWT Handler","severity":"medium","exploited":false,"published_at":"2026-06-21T02:16:41.073+00:00","url":"https://junglewise.ai/threats/cve-2026-12771-berriai-litellm-improper-authorization-in-m2m-jwt-handler"},{"cve":"CVE-2026-12770","cvss":5.4,"epss":0.0057,"slug":"cve-2026-12770-berriai-litellm-improper-authorization-in-key-management","title":"BerriAI LiteLLM improper authorization in key management endpoints","severity":"medium","exploited":false,"published_at":"2026-06-21T01:16:22.847+00:00","url":"https://junglewise.ai/threats/cve-2026-12770-berriai-litellm-improper-authorization-in-key-management"},{"cve":"CVE-2026-47102","cvss":8.8,"epss":0.0082,"slug":"cve-2026-47102-berriai-litellm-privilege-escalation-in-user-update-endpoint","title":"BerriAI LiteLLM privilege escalation in user update endpoint","severity":"high","exploited":false,"published_at":"2026-05-21T21:16:32.557+00:00","url":"https://junglewise.ai/threats/cve-2026-47102-berriai-litellm-privilege-escalation-in-user-update-endpoint"},{"cve":"CVE-2026-47101","cvss":8.8,"epss":0.0133,"slug":"cve-2026-47101-berriai-litellm-privilege-escalation-in-api-key-generation","title":"BerriAI LiteLLM privilege escalation in API key generation","severity":"high","exploited":false,"published_at":"2026-05-21T21:16:32.413+00:00","url":"https://junglewise.ai/threats/cve-2026-47101-berriai-litellm-privilege-escalation-in-api-key-generation"},{"cve":"CVE-2026-42271","cvss":8.8,"epss":0.1275,"slug":"cve-2026-42271-berriai-litellm-os-command-injection-in-mcp-test-endpoints","title":"BerriAI LiteLLM OS command injection in MCP test endpoints","severity":"critical","exploited":true,"published_at":"2026-05-08T04:16:21.82+00:00","url":"https://junglewise.ai/threats/cve-2026-42271-berriai-litellm-os-command-injection-in-mcp-test-endpoints"},{"cve":"CVE-2026-42208","cvss":9.8,"epss":0.0577,"slug":"cve-2026-42208-berriai-litellm-sql-injection-in-proxy-api-key-verification","title":"BerriAI LiteLLM SQL injection in Proxy API key verification","severity":"critical","exploited":true,"published_at":"2026-05-08T04:16:19.923+00:00","url":"https://junglewise.ai/threats/cve-2026-42208-berriai-litellm-sql-injection-in-proxy-api-key-verification"},{"cve":"CVE-2026-42203","cvss":8.8,"epss":0.0066,"slug":"cve-2026-42203-berriai-litellm-code-injection-in-prompts-test-endpoint","title":"BerriAI LiteLLM code injection in /prompts/test endpoint","severity":"high","exploited":false,"published_at":"2026-05-08T04:16:19.45+00:00","url":"https://junglewise.ai/threats/cve-2026-42203-berriai-litellm-code-injection-in-prompts-test-endpoint"}],"vendor":{"hub":true,"name":"Berriai","slug":"berriai","description":"<UNKNOWN>","url":"https://junglewise.ai/threats/vendors/berriai"},"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":1,"exploited":1,"vulnerabilities":4},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":1,"exploited":0,"vulnerabilities":1},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":1}],"most_severe":[{"cve":"CVE-2026-42208","cvss":9.8,"epss":0.0577,"slug":"cve-2026-42208-berriai-litellm-sql-injection-in-proxy-api-key-verification","title":"BerriAI LiteLLM SQL injection in Proxy API key verification","severity":"critical","exploited":true,"published_at":"2026-05-08T04:16:19.923+00:00","url":"https://junglewise.ai/threats/cve-2026-42208-berriai-litellm-sql-injection-in-proxy-api-key-verification"},{"cve":"CVE-2026-42271","cvss":8.8,"epss":0.1275,"slug":"cve-2026-42271-berriai-litellm-os-command-injection-in-mcp-test-endpoints","title":"BerriAI LiteLLM OS command injection in MCP test endpoints","severity":"critical","exploited":true,"published_at":"2026-05-08T04:16:21.82+00:00","url":"https://junglewise.ai/threats/cve-2026-42271-berriai-litellm-os-command-injection-in-mcp-test-endpoints"},{"cve":"CVE-2026-59822","cvss":4,"epss":0.0084,"slug":"cve-2026-59822-berriai-litellm-authentication-bypass-in-mcp-endpoint","title":"BerriAI LiteLLM authentication bypass in MCP endpoint","severity":"critical","exploited":true,"published_at":"2026-07-08T20:16:57.683+00:00","url":"https://junglewise.ai/threats/cve-2026-59822-berriai-litellm-authentication-bypass-in-mcp-endpoint"},{"cve":"CVE-2024-2952","cvss":9.8,"epss":0.0127,"slug":"cve-2024-2952-berriai-litellm-ssti-in-completions-endpoint","title":"BerriAI LiteLLM SSTI in completions endpoint","severity":"critical","exploited":false,"published_at":"2024-04-10T18:30:48+00:00","url":"https://junglewise.ai/threats/cve-2024-2952-berriai-litellm-ssti-in-completions-endpoint"},{"cve":"CVE-2026-37004","cvss":9.8,"epss":0.008,"slug":"cve-2026-37004-berriai-litellm-server-side-template-injection-in-prompts","title":"BerriAI litellm <=1.82.4 is vulnerable to Server-Side Template Injection (SSTI), which allows unauthenticated remote attackers to execute ar","severity":"critical","exploited":false,"published_at":"2026-08-27T20:17:41.27+00:00","url":"https://junglewise.ai/threats/cve-2026-37004-berriai-litellm-server-side-template-injection-in-prompts"},{"cve":"CVE-2026-35030","cvss":9.1,"epss":0.0088,"slug":"cve-2026-35030-berriai-litellm-authentication-bypass-via-oidc-cache-key","title":"BerriAI LiteLLM authentication bypass via OIDC cache key collision","severity":"critical","exploited":false,"published_at":"2026-04-06T17:17:12.65+00:00","url":"https://junglewise.ai/threats/cve-2026-35030-berriai-litellm-authentication-bypass-via-oidc-cache-key"},{"cve":"CVE-2026-49468","cvss":3.1,"epss":0.0082,"slug":"cve-2026-49468-berriai-litellm-authentication-bypass-via-host-header-injection","title":"BerriAI LiteLLM authentication bypass via Host header injection","severity":"critical","exploited":false,"published_at":"2026-06-22T21:16:25.19+00:00","url":"https://junglewise.ai/threats/cve-2026-49468-berriai-litellm-authentication-bypass-via-host-header-injection"},{"cve":"CVE-2026-35029","cvss":8.8,"epss":0.0398,"slug":"cve-2026-35029-berriai-litellm-incorrect-authorization-in-config-update-endpoint","title":"BerriAI LiteLLM incorrect authorization in config update endpoint","severity":"high","exploited":false,"published_at":"2026-04-06T17:17:12.353+00:00","url":"https://junglewise.ai/threats/cve-2026-35029-berriai-litellm-incorrect-authorization-in-config-update-endpoint"},{"cve":"CVE-2026-40217","cvss":8.8,"epss":0.034,"slug":"cve-2026-40217-berriai-litellm-remote-code-execution-in-guardrails-component","title":"BerriAI LiteLLM remote code execution in guardrails component","severity":"high","exploited":false,"published_at":"2026-04-10T14:16:36.307+00:00","url":"https://junglewise.ai/threats/cve-2026-40217-berriai-litellm-remote-code-execution-in-guardrails-component"},{"cve":"CVE-2026-47101","cvss":8.8,"epss":0.0133,"slug":"cve-2026-47101-berriai-litellm-privilege-escalation-in-api-key-generation","title":"BerriAI LiteLLM privilege escalation in API key generation","severity":"high","exploited":false,"published_at":"2026-05-21T21:16:32.413+00:00","url":"https://junglewise.ai/threats/cve-2026-47101-berriai-litellm-privilege-escalation-in-api-key-generation"}],"generated_at":"2026-09-26T12:07:00.15149+00:00","technologies":[{"name":"Berriai LiteLLM","slug":"litellm","vulnerabilities":30,"url":"https://junglewise.ai/threats/technologies/litellm"}]}