VDB
Sign up
HIGH7.3

GHSA-j37q-q7p9-vpwm

LiteLLM: SSO Debug Flow Has Improper Authentication

Details

A vulnerability was determined in BerriAI litellm up to 1.82.2. This affects the function json.dumps of the file litellm/proxy/management_endpoints/ui_sso.py of the component SSO Debug Flow. Executing a manipulation can lead to missing authentication. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/litellm
Introduced in: 0

No fixed version published yet for litellm (pip). Pin to a known-safe version or switch to an alternative.

References