PT-2026-98928 · Berriai · Litellm
CVSS v3.1
7.7
High
| Vector | AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
BerriAI LiteLLM versions prior to 1.101.0-rc.1
Description
A tenant isolation bypass exists in the semantic cache layer due to a metadata key mismatch between the
get semantic cache tenant scope() and get metadata variable name() functions. Authenticated users with a valid virtual key can exploit this by submitting semantically similar prompts to the '/v1/responses' and '/bedrock/*' endpoints. This allows an attacker to retrieve cached responses belonging to other tenants, potentially exposing personally identifiable information, financial data, or source code. Additionally, this can lead to the execution of attacker-supplied tool calls under victim credentials if cached function call or tool calls payloads are returned to a different principal.Recommendations
Upgrade to version 1.101.0-rc.1.
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Litellm