PT-2026-51208 · Berriai · Litellm

·

CVE-2026-12795

·

Published

2026-06-21

·

Updated

2026-06-24

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions BerriAI litellm versions prior to 1.82.3
Description An authentication bypass exists in the SSO Debug Flow component. A remote attacker can manipulate the json.dumps() function within the file litellm/proxy/management endpoints/ui sso.py, which can lead to missing authentication.
Recommendations Update to version 1.82.3 or later. As a temporary workaround, restrict access to the SSO Debug Flow component or the json.dumps() function in litellm/proxy/management endpoints/ui sso.py to minimize the risk of exploitation.

Exploit

Fix

Missing Authentication

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-12795
GHSA-J37Q-Q7P9-VPWM

Affected Products

Litellm