PT-2026-51182 · Litellm · Litellm
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
litellm versions prior to 1.63.2
Description
An improper authorization issue exists in the Admin Key Handler component within the file
litellm/proxy/management endpoints/key management endpoints.py. This flaw allows a remote attacker to bypass authorization requirements through an unknown function.Recommendations
Apply patch 23781 to resolve the issue.
Exploit
Fix
Incorrect Privilege Assignment
Improper Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Litellm