HIGH7.3
GHSA-j37q-q7p9-vpwm
LiteLLM: SSO Debug Flow Has Improper Authentication
Details
A vulnerability was determined in BerriAI litellm up to 1.82.2. This affects the function json.dumps of the file litellm/proxy/management_endpoints/ui_sso.py of the component SSO Debug Flow. Executing a manipulation can lead to missing authentication. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure.
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI/litellm
Introduced in:
0No fixed version published yet for litellm (pip). Pin to a known-safe version or switch to an alternative.
References
- https://nvd.nist.gov/vuln/detail/CVE-2026-12795[ADVISORY]
- https://gist.github.com/YLChen-007/9b13c75a3a73187a4082cc6df0b100d3[WEB]
- https://github.com/BerriAI/litellm[PACKAGE]
- https://vuldb.com/cve/CVE-2026-12795[WEB]
- https://vuldb.com/submit/811286[WEB]
- https://vuldb.com/vuln/372557[WEB]
- https://vuldb.com/vuln/372557/cti[WEB]