PT-2026-51212 · Berriai · Litellm
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
BerriAI litellm versions prior to 1.82.3
Description
A server-side request forgery (SSRF) exists in the MCP OpenAPI Spec Loader component. The issue occurs within the
load openapi spec async() function located in the litellm/proxy/ experimental/mcp server/openapi to mcp generator.py file. A remote attacker can trigger this by manipulating the spec path argument.Recommendations
Update to a version later than 1.82.2.
As a temporary workaround, restrict access to the
load openapi spec async() function until the update is applied.Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Litellm