71 Total advisories
70 Vulnerabilities
1 Malware

Dependency scanning

Check whether litellm is in your codebase

Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.

Vulnerabilities

UNKNOWN
PyPI

CVE-2026-59823

LiteLLM Proxy has server-side request forgery via the `user_config` request parameter

MEDIUM 6.3
PyPI

CVE-2026-12797

BerriAI litellm has Security Feature Bypass in BannedKeywords and AzureContentSafety Guardrails via call_type Mismatch on Async Endpoints

MEDIUM 4.3
PyPI

CVE-2026-12799

BerriAI litellm: UI User Enumeration leads to System-Wide Information Disclosure

MEDIUM 6.3
PyPI

CVE-2026-12798

BerriAI litellm has SSRF via Unvalidated spec_path URL in MCP OpenAPI Spec Loader

MEDIUM 6.3
PyPI

CVE-2026-12796

BerriAI litellm: SSO Login Does Not Invalidate Previous UI Session Tokens

HIGH 7.3
PyPI

CVE-2026-12773

LiteLLM: MCP Proxy Has Improper Authentication

MEDIUM 5.4
PyPI

CVE-2026-12770

LiteLLM: Admin Key Handler Has Improper Authorization

HIGH 7.3
PyPI

CVE-2026-12795

LiteLLM: SSO Debug Flow Has Improper Authentication

MEDIUM 5.0
PyPI

CVE-2026-12771

LiteLLM: M2M JWT Handler Has Improper Authorization

MEDIUM 6.3
PyPI

CVE-2026-12772

LiteLLM: PROXY_ADMIN database API Key Generator Has Insufficient Session Expiration

CRITICAL 9.8
PyPI

CVE-2026-37004

LiteLLM vulnerable to server-side template injection in the /prompts/test endpoint

CRITICAL 9.8
PyPI

CVE-2026-37004

LiteLLM vulnerable to server-side template injection in the /prompts/test endpoint

UNKNOWN
PyPI KEV

CVE-2026-59822

LiteLLM: MCP Authentication Bypass via OAuth2 Passthrough Fallback

UNKNOWN
PyPI

CVE-2026-59821

LiteLLM: Custom Code Guardrails production endpoints bypass code safety checks

UNKNOWN
PyPI

CVE-2026-59820

LiteLLM: Arbitrary file write via path traversal in Skills archive extraction

UNKNOWN
PyPI

CVE-2026-59819

LiteLLM: Local file read via request-supplied OIDC file references

HIGH 8.8
PyPI

CVE-2026-40217

LiteLLM has a sandbox escape in custom-code guardrail

HIGH 8.8
PyPI

CVE-2026-47101

LiteLLM allows an authenticated internal_user to create API keys with access to routes that their role does not permit

HIGH 8.8
PyPI KEV

CVE-2026-42271

LiteLLM: Authenticated command execution via MCP stdio test endpoints

CRITICAL 9.8
PyPI KEV

CVE-2026-42208

LiteLLM has SQL Injection in Proxy API key verification

HIGH 7.5
PyPI

CVE-2024-6587

LiteLLM Server-Side Request Forgery (SSRF) vulnerability

CRITICAL 9.8
PyPI

CVE-2026-49468

LiteLLM: Authentication Bypass via Host Header Injection

HIGH 8.8
PyPI

CVE-2026-47102

LiteLLM allows a user to modify their own user_role via the /user/update endpoint

UNKNOWN
PyPI

CVE-2026-42203

LiteLLM: Server-Side Template Injection in /prompts/test endpoint

UNKNOWN
PyPI

CVE-2026-35030

LiteLLM: Authentication bypass via OIDC userinfo cache key collision

UNKNOWN
PyPI

GHSA-69x8-hrgq-fjj8

LiteLLM: Password hash exposure and pass-the-hash authentication bypass

UNKNOWN
PyPI

CVE-2026-35029

LiteLLM: Privilege escalation via unrestricted proxy configuration endpoint

HIGH 8.8
PyPI

GHSA-3926-2jvf-fg29

Duplicate Advisory: LiteLLM has a sandbox escape in custom-code guardrail

HIGH 7.5
PyPI

CVE-2025-0330

LiteLLM Has a Leakage of Langfuse API Keys

HIGH 7.5
PyPI

CVE-2024-8984

LiteLLM Vulnerable to Denial of Service (DoS) via Crafted HTTP Request

MEDIUM 5.3
PyPI

CVE-2024-5710

litellm vulnerable to improper access control in team management

CRITICAL 9.8
PyPI

CVE-2024-5751

litellm vulnerable to remote code execution based on using eval unsafely

MEDIUM 6.4
PyPI

CVE-2024-5225

SQL injection in litellm

MEDIUM 4.9
PyPI

CVE-2024-4890

SQL injection in litellm

HIGH 7.2
PyPI

CVE-2024-4264

litellm passes untrusted data to `eval` function without sanitization

CRITICAL 9.8
PyPI

CVE-2024-2952

LiteLLM has Server-Side Template Injection vulnerability in /completions endpoint

HIGH 7.5
PyPI

CVE-2024-9606

LiteLLM Reveals Portion of API Key via a Logging File

HIGH 8.1
PyPI

CVE-2025-0628

LiteLLM Has an Improper Authorization Vulnerability

HIGH 7.5
PyPI

CVE-2024-10188

LiteLLM Vulnerable to Denial of Service (DoS)

HIGH 8.8
PyPI

CVE-2024-6825

LiteLLM Vulnerable to Remote Code Execution (RCE)

MEDIUM 6.5
PyPI

CVE-2024-4888

Arbitrary file deletion in litellm

UNKNOWN
PyPI

CVE-2026-59820

LiteLLM: Arbitrary file write via path traversal in Skills archive extraction

UNKNOWN
PyPI

CVE-2026-59821

LiteLLM: Custom Code Guardrails production endpoints bypass code safety checks

UNKNOWN
PyPI KEV

CVE-2026-59822

LiteLLM: MCP Authentication Bypass via OAuth2 Passthrough Fallback

UNKNOWN
PyPI

CVE-2026-59819

LiteLLM: Local file read via request-supplied OIDC file references

HIGH 8.8
PyPI

CVE-2026-40217

LiteLLM has a sandbox escape in custom-code guardrail

UNKNOWN
PyPI

CVE-2026-42203

LiteLLM: Server-Side Template Injection in /prompts/test endpoint

HIGH 8.8
PyPI

CVE-2026-47102

LiteLLM allows a user to modify their own user_role via the /user/update endpoint

HIGH 8.8
PyPI KEV

CVE-2026-42271

LiteLLM: Authenticated command execution via MCP stdio test endpoints

HIGH 8.8
PyPI

CVE-2026-47101

LiteLLM allows an authenticated internal_user to create API keys with access to routes that their role does not permit

UNKNOWN
PyPI

CVE-2026-35029

LiteLLM: Privilege escalation via unrestricted proxy configuration endpoint

HIGH 7.5
PyPI

CVE-2024-10188

LiteLLM Vulnerable to Denial of Service (DoS)

MEDIUM 6.4
PyPI

CVE-2024-5225

SQL injection in litellm

HIGH 7.5
PyPI

CVE-2024-9606

LiteLLM Reveals Portion of API Key via a Logging File

HIGH 8.1
PyPI

CVE-2025-0628

LiteLLM Has an Improper Authorization Vulnerability

HIGH 7.5
PyPI

CVE-2024-6587

LiteLLM Server-Side Request Forgery (SSRF) vulnerability

HIGH 7.2
PyPI

CVE-2024-4264

litellm passes untrusted data to `eval` function without sanitization

HIGH 7.5
PyPI

CVE-2025-0330

LiteLLM Has a Leakage of Langfuse API Keys

MEDIUM 4.9
PyPI

CVE-2024-4890

SQL injection in litellm

HIGH 7.5
PyPI

CVE-2024-8984

LiteLLM Vulnerable to Denial of Service (DoS) via Crafted HTTP Request

HIGH 8.8
PyPI

CVE-2024-6825

LiteLLM Vulnerable to Remote Code Execution (RCE)

MEDIUM 6.5
PyPI

CVE-2024-4888

Arbitrary file deletion in litellm

MEDIUM 5.3
PyPI

CVE-2024-5710

litellm vulnerable to improper access control in team management

CRITICAL 9.8
PyPI KEV

CVE-2026-42208

LiteLLM has SQL Injection in Proxy API key verification

UNKNOWN
PyPI

CVE-2026-35030

LiteLLM: Authentication bypass via OIDC userinfo cache key collision

CRITICAL 9.8
PyPI

CVE-2024-5751

litellm vulnerable to remote code execution based on using eval unsafely

UNKNOWN
PyPI

CVE-2026-49468

LiteLLM: Authentication Bypass via Host Header Injection

CRITICAL 9.8
PyPI

CVE-2024-2952

LiteLLM has Server-Side Template Injection vulnerability in /completions endpoint

UNKNOWN
PyPI

GHSA-5mg7-485q-xm76

Two LiteLLM versions published containing credential harvesting malware

UNKNOWN
PyPI

MAL-2026-2144

Two litellm versions published containing credential harvesting malware

Learn What is SAST?

Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →

Ready to move

Start Securing

Free, no credit card | First findings in minutes