PT-2026-51208 · Berriai · Litellm
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
BerriAI litellm versions prior to 1.82.3
Description
An authentication bypass exists in the SSO Debug Flow component. A remote attacker can manipulate the
json.dumps() function within the file litellm/proxy/management endpoints/ui sso.py, which can lead to missing authentication.Recommendations
Update to version 1.82.3 or later.
As a temporary workaround, restrict access to the SSO Debug Flow component or the
json.dumps() function in litellm/proxy/management endpoints/ui sso.py to minimize the risk of exploitation.Exploit
Fix
Missing Authentication
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Litellm