Dependency scanning
Check whether litellm is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Malware Advisories
Vulnerabilities
CVE-2026-59823
LiteLLM Proxy has server-side request forgery via the `user_config` request parameter
CVE-2026-12797
BerriAI litellm has Security Feature Bypass in BannedKeywords and AzureContentSafety Guardrails via call_type Mismatch on Async Endpoints
CVE-2026-12799
BerriAI litellm: UI User Enumeration leads to System-Wide Information Disclosure
CVE-2026-12798
BerriAI litellm has SSRF via Unvalidated spec_path URL in MCP OpenAPI Spec Loader
CVE-2026-12796
BerriAI litellm: SSO Login Does Not Invalidate Previous UI Session Tokens
CVE-2026-12773
LiteLLM: MCP Proxy Has Improper Authentication
CVE-2026-12770
LiteLLM: Admin Key Handler Has Improper Authorization
CVE-2026-12795
LiteLLM: SSO Debug Flow Has Improper Authentication
CVE-2026-12771
LiteLLM: M2M JWT Handler Has Improper Authorization
CVE-2026-12772
LiteLLM: PROXY_ADMIN database API Key Generator Has Insufficient Session Expiration
CVE-2026-37004
LiteLLM vulnerable to server-side template injection in the /prompts/test endpoint
CVE-2026-37004
LiteLLM vulnerable to server-side template injection in the /prompts/test endpoint
CVE-2026-59822
LiteLLM: MCP Authentication Bypass via OAuth2 Passthrough Fallback
CVE-2026-59821
LiteLLM: Custom Code Guardrails production endpoints bypass code safety checks
CVE-2026-59820
LiteLLM: Arbitrary file write via path traversal in Skills archive extraction
CVE-2026-59819
LiteLLM: Local file read via request-supplied OIDC file references
CVE-2026-40217
LiteLLM has a sandbox escape in custom-code guardrail
CVE-2026-47101
LiteLLM allows an authenticated internal_user to create API keys with access to routes that their role does not permit
CVE-2026-42271
LiteLLM: Authenticated command execution via MCP stdio test endpoints
CVE-2026-42208
LiteLLM has SQL Injection in Proxy API key verification
CVE-2024-6587
LiteLLM Server-Side Request Forgery (SSRF) vulnerability
CVE-2026-49468
LiteLLM: Authentication Bypass via Host Header Injection
CVE-2026-47102
LiteLLM allows a user to modify their own user_role via the /user/update endpoint
CVE-2026-42203
LiteLLM: Server-Side Template Injection in /prompts/test endpoint
CVE-2026-35030
LiteLLM: Authentication bypass via OIDC userinfo cache key collision
GHSA-69x8-hrgq-fjj8
LiteLLM: Password hash exposure and pass-the-hash authentication bypass
CVE-2026-35029
LiteLLM: Privilege escalation via unrestricted proxy configuration endpoint
GHSA-3926-2jvf-fg29
Duplicate Advisory: LiteLLM has a sandbox escape in custom-code guardrail
CVE-2025-0330
LiteLLM Has a Leakage of Langfuse API Keys
CVE-2024-8984
LiteLLM Vulnerable to Denial of Service (DoS) via Crafted HTTP Request
CVE-2024-5710
litellm vulnerable to improper access control in team management
CVE-2024-5751
litellm vulnerable to remote code execution based on using eval unsafely
CVE-2024-5225
SQL injection in litellm
CVE-2024-4890
SQL injection in litellm
CVE-2024-4264
litellm passes untrusted data to `eval` function without sanitization
CVE-2024-2952
LiteLLM has Server-Side Template Injection vulnerability in /completions endpoint
CVE-2024-9606
LiteLLM Reveals Portion of API Key via a Logging File
CVE-2025-0628
LiteLLM Has an Improper Authorization Vulnerability
CVE-2024-10188
LiteLLM Vulnerable to Denial of Service (DoS)
CVE-2024-6825
LiteLLM Vulnerable to Remote Code Execution (RCE)
CVE-2024-4888
Arbitrary file deletion in litellm
CVE-2026-59820
LiteLLM: Arbitrary file write via path traversal in Skills archive extraction
CVE-2026-59821
LiteLLM: Custom Code Guardrails production endpoints bypass code safety checks
CVE-2026-59822
LiteLLM: MCP Authentication Bypass via OAuth2 Passthrough Fallback
CVE-2026-59819
LiteLLM: Local file read via request-supplied OIDC file references
CVE-2026-40217
LiteLLM has a sandbox escape in custom-code guardrail
CVE-2026-42203
LiteLLM: Server-Side Template Injection in /prompts/test endpoint
CVE-2026-47102
LiteLLM allows a user to modify their own user_role via the /user/update endpoint
CVE-2026-42271
LiteLLM: Authenticated command execution via MCP stdio test endpoints
CVE-2026-47101
LiteLLM allows an authenticated internal_user to create API keys with access to routes that their role does not permit
CVE-2026-35029
LiteLLM: Privilege escalation via unrestricted proxy configuration endpoint
CVE-2024-10188
LiteLLM Vulnerable to Denial of Service (DoS)
CVE-2024-5225
SQL injection in litellm
CVE-2024-9606
LiteLLM Reveals Portion of API Key via a Logging File
CVE-2025-0628
LiteLLM Has an Improper Authorization Vulnerability
CVE-2024-6587
LiteLLM Server-Side Request Forgery (SSRF) vulnerability
CVE-2024-4264
litellm passes untrusted data to `eval` function without sanitization
CVE-2025-0330
LiteLLM Has a Leakage of Langfuse API Keys
CVE-2024-4890
SQL injection in litellm
CVE-2024-8984
LiteLLM Vulnerable to Denial of Service (DoS) via Crafted HTTP Request
CVE-2024-6825
LiteLLM Vulnerable to Remote Code Execution (RCE)
CVE-2024-4888
Arbitrary file deletion in litellm
CVE-2024-5710
litellm vulnerable to improper access control in team management
CVE-2026-42208
LiteLLM has SQL Injection in Proxy API key verification
CVE-2026-35030
LiteLLM: Authentication bypass via OIDC userinfo cache key collision
CVE-2024-5751
litellm vulnerable to remote code execution based on using eval unsafely
CVE-2026-49468
LiteLLM: Authentication Bypass via Host Header Injection
CVE-2024-2952
LiteLLM has Server-Side Template Injection vulnerability in /completions endpoint
GHSA-5mg7-485q-xm76
Two LiteLLM versions published containing credential harvesting malware
MAL-2026-2144
Two litellm versions published containing credential harvesting malware
Browse more PyPI advisories
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes