Skip to content
Threat Feed

CPE

Cpe:2.3:a:litellm:litellm:*:*:*:*:*:*:*:*

4 briefs RSS
high advisory

Weak Authentication Vulnerability in LiteLLM (CVE-2026-93355)

LiteLLM contains a critical authentication flaw where failure to validate JWT email claims allows attackers to impersonate arbitrary users and escalate to administrative privileges.

LiteLLM
2t 1c
medium advisory

Security Bypass Vulnerability in TIBCO JasperReports

A vulnerability, CVE-2024-5225, in TIBCO JasperReports enables remote, unauthenticated attackers to bypass application-level security controls.

JasperReports
1t 1c
high advisory

LiteLLM MCP Authentication Bypass via OAuth2 Passthrough Fallback

An authentication bypass vulnerability (CVE-2026-59822) exists in LiteLLM's MCP Streamable HTTP endpoint, affecting versions prior to 1.84.0, allowing an unauthenticated attacker to exploit a fallback path that replaces failed key validation with an empty authentication object, leading to the establishment of an authenticated MCP session using arbitrary Bearer tokens, enabling access to configured MCP tools and connected services.

LiteLLM authentication-bypass api-security web-vulnerability
1t 1c updated
high advisory

LiteLLM Authenticated Command Injection via MCP stdio Test Endpoints (CVE-2026-42271)

A command injection vulnerability exists in LiteLLM versions 1.74.2 to < 1.83.7, allowing authenticated users with a valid API key to execute arbitrary OS commands as root via the MCP stdio transport through the `POST /mcp-rest/test/connection` and `POST /mcp-rest/test/tools/list` endpoints, especially in default Docker deployments, and a public exploit is available.

LiteLLM command injection rce CVE-2026-42271
2r 1t 1c