Server-Side Request Forgery Vulnerability in BerriAI litellm
CVE-2026-12774

5.3MEDIUM

Key Information:

Vendor

Berriai

Status
Vendor
CVE Published:
21 June 2026

Badges

๐Ÿ‘พ Exploit Exists๐ŸŸก Public PoC

What is CVE-2026-12774?

A security vulnerability in BerriAI's litellm has been identified, affecting versions up to 1.82.2. This issue arises in the function _execute_with_mcp_client within the MCP Server Connection Testing component, specifically found in the file litellm/proxy/_experimental/mcp_server/rest_endpoints.py. The flaw allows for server-side request forgery, enabling potential attackers to manipulate server requests. This exploit is publicly disclosed and could be leveraged for remote attacks, posing a significant risk to users. Early communication with the vendor regarding this vulnerability has been made.

Affected Version(s)

litellm 1.82.0

litellm 1.82.1

litellm 1.82.2

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Eric-c (VulDB User)
VulDB CNA Team
.