Obsidian Security Discovers Critical LiteLLM Vulnerabilities
Obsidian Security, a cybersecurity company, disclosed a chain of three critical vulnerabilities in LiteLLM that allow low-privilege users to take over AI…
Obsidian Security, a cybersecurity company, disclosed a chain of three critical vulnerabilities in LiteLLM that allow low-privilege users to take over AI…
CVE-2026-47101 is an authorization bypass vulnerability in LiteLLM where the allowed_routes field is not validated against user roles, allowing low-privilege users to…
CVE-2026-47102 is a privilege escalation vulnerability in LiteLLM's /user/update endpoint, which does not restrict field updates, allowing users to self-promote to proxy_admin…
BerriAI LiteLLM Command Injection Vulnerability Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of…
BerriAI LiteLLM SQL Injection Vulnerability Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of…