Proxy Server Vulnerability in LiteLLM by BerriAI
CVE-2026-84377
What is CVE-2026-84377?
LiteLLM, developed by BerriAI, is a proxy server designed to facilitate access to large language model APIs. A vulnerability existed prior to the releases 1.88.6 and 1.96.2, where authenticated users of the LiteLLM proxy could exploit insufficient request validation, allowing rerouting outbound provider calls. This exploited the system's weak checks on sensitive parameters, enabling attackers to redirect data and reveal sensitive credentials stored within the proxy. The vulnerability affected critical routing and credential parameters, compromising the integrity of API calls and potentially exposing upstream service credentials. This risk has been effectively mitigated in the updated versions of the software.
Affected Version(s)
litellm < 1.88.6 < 1.88.6
litellm >= 1.89.0, < 1.96.2 < 1.89.0, 1.96.2
