Products: 1
    Vulnerabilities: 31
    Known Exploited: 3
    7
    Critical Level Threats
    16
    High Level Threats
    8
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-84377

    LiteLLM: Authenticated SSRF and provider-credential exfiltration via unvalidated request-body routing parameters

    Last Modified: Sep 03, 2026
    Published: Sep 02, 2026

    CVE-2026-37004

    Server‑Side Template Injection in BerriAI litellm Enables Remote Code Execution

    Last Modified: Sep 01, 2026
    Published: Aug 27, 2026

    CVE-2026-30623

    LiteLLM 1.18.10 contains a remote code execution vulnerability in its MCP server creation functionality. The application allows users to add MCP servers via a JSON configuration specifying arbitrary command and args values. LiteLLM executes these values on the host without validation, enabling attackers to run arbitrary operating system commands. Successful exploitation may result in remote code execution with the privileges of the LiteLLM process.

    Last Modified: Jul 16, 2026
    Published: Jul 15, 2026

    CVE-2026-59819

    LiteLLM: Local file read via request-supplied OIDC file references

    Last Modified: Jul 10, 2026
    Published: Jul 08, 2026

    CVE-2026-59822

    LiteLLM: MCP Authentication Bypass via OAuth2 Passthrough Fallback

    Last Modified: Sep 02, 2026
    Published: Jul 08, 2026
    Items Per Page