© 2025-2026 PySpect
First version without a known vulnerability: 1.85.0.dev1
LiteLLM Proxy has server-side request forgery via the `user_config` request parameter
Fixed in: 1.83.9
LiteLLM vulnerable to server-side template injection in the /prompts/test endpoint
Fixed in: 1.83.7
LiteLLM: Custom Code Guardrails production endpoints bypass code safety checks
Fixed in: 1.82.0
LiteLLM: MCP Authentication Bypass via OAuth2 Passthrough Fallback
Fixed in: 1.84.0
LiteLLM: Local file read via request-supplied OIDC file references
Fixed in: 1.83.10
LiteLLM: Arbitrary file write via path traversal in Skills archive extraction
Fixed in: 1.83.7
BerriAI litellm has SSRF via Unvalidated spec_path URL in MCP OpenAPI Spec Loader
BerriAI litellm: UI User Enumeration leads to System-Wide Information Disclosure
BerriAI litellm has Security Feature Bypass in BannedKeywords and AzureContentSafety Guardrails via call_type Mismatch on Async Endpoints
BerriAI litellm: SSO Login Does Not Invalidate Previous UI Session Tokens
LiteLLM: SSO Debug Flow Has Improper Authentication
LiteLLM: MCP Proxy Has Improper Authentication
Fixed in: 1.84.0
LiteLLM: Admin Key Handler Has Improper Authorization
LiteLLM: PROXY_ADMIN database API Key Generator Has Insufficient Session Expiration
LiteLLM: M2M JWT Handler Has Improper Authorization
LiteLLM: Authentication Bypass via Host Header Injection
Fixed in: 1.84.0
LiteLLM allows a user to modify their own user_role via the /user/update endpoint
Fixed in: 1.83.10
LiteLLM allows an authenticated internal_user to create API keys with access to routes that their role does not permit
Fixed in: 1.83.14
LiteLLM has a sandbox escape in custom-code guardrail
Fixed in: 1.83.10
LiteLLM: Authenticated command execution via MCP stdio test endpoints
Fixed in: 1.83.7
LiteLLM has SQL Injection in Proxy API key verification
Fixed in: 1.83.7
LiteLLM: Server-Side Template Injection in /prompts/test endpoint
Fixed in: 1.83.7
LiteLLM: Password hash exposure and pass-the-hash authentication bypass
Fixed in: 1.83.0
LiteLLM: Authentication bypass via OIDC userinfo cache key collision
Fixed in: 1.83.0
LiteLLM: Privilege escalation via unrestricted proxy configuration endpoint
Fixed in: 1.83.0
Two LiteLLM versions published containing credential harvesting malware
Malicious code in litellm (PyPI)
LiteLLM Has a Leakage of Langfuse API Keys
LiteLLM Has an Improper Authorization Vulnerability
Fixed in: 1.61.15
LiteLLM Reveals Portion of API Key via a Logging File
Fixed in: 1.44.12
LiteLLM Vulnerable to Denial of Service (DoS) via Crafted HTTP Request
Fixed in: 1.56.2
LiteLLM Vulnerable to Remote Code Execution (RCE)
LiteLLM Vulnerable to Denial of Service (DoS)
Fixed in: 1.53.1.dev1
LiteLLM Server-Side Request Forgery (SSRF) vulnerability
Fixed in: 1.44.8
litellm vulnerable to remote code execution based on using eval unsafely
Fixed in: 1.40.16
litellm vulnerable to improper access control in team management
Fixed in: 1.40.15
Arbitrary file deletion in litellm
Fixed in: 1.35.36
SQL injection in litellm
SQL injection in litellm
Fixed in: 1.40.0
litellm passes untrusted data to `eval` function without sanitization
LiteLLM has Server-Side Template Injection vulnerability in /completions endpoint
Fixed in: 1.34.42