{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/litellm--1.101.0-rc.1/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:berriai:litellm:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.7,"id":"CVE-2026-89032"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["LiteLLM (\u003c 1.101.0-rc.1)"],"_cs_severities":["high"],"_cs_tags":["tenant-bypass","cve-2026-89032","cloud-security"],"_cs_type":"advisory","_cs_vendors":["BerriAI"],"content_html":"\u003cp\u003eBerriAI LiteLLM versions before 1.101.0-rc.1 contain a tenant isolation bypass vulnerability located within the semantic cache layer. The flaw arises from a mismatch between the functions _get_semantic_cache_tenant_scope() and _get_metadata_variable_name(), which manage the scoping of cache entries. An attacker with a valid virtual key can exploit this logical error by submitting specifically crafted prompts.\u003c/p\u003e\n\u003cp\u003eBy targeting routes such as /v1/responses or /bedrock/*, an authenticated user can retrieve cached responses belonging to other tenants. This unauthorized access can lead to the exposure of sensitive information, including personally identifiable information (PII), financial data, and proprietary source code. Furthermore, the vulnerability enables attackers to manipulate agentic front-ends by injecting malicious payloads into the cache; when retrieved by a different principal, these cached function_call or tool_calls payloads may trigger unintended tool execution under the victim's credentials.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability results in a loss of data confidentiality and integrity for multi-tenant environments using LiteLLM. Successful exploitation allows unauthorized access to sensitive tenant data and the potential for privilege escalation or remote code execution within agentic workflows through tool call manipulation.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade BerriAI LiteLLM to version 1.101.0-rc.1 or later immediately to resolve the metadata key mismatch in the semantic cache layer.\u003c/li\u003e\n\u003cli\u003eImplement strict access controls and audit logging for sensitive endpoints including /v1/responses and routes under /bedrock/*.\u003c/li\u003e\n\u003cli\u003eReview cached entries for unexpected or anomalous function_call parameters if suspicion of exploitation arises.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-25T18:54:40Z","date_published":"2026-09-25T18:54:40Z","id":"https://feed.craftedsignal.io/briefs/2026-09-litellm-bypass/","summary":"BerriAI LiteLLM versions prior to 1.101.0-rc.1 are vulnerable to a tenant isolation bypass that allows authenticated users to access other tenants' cached responses through a metadata key mismatch.","title":"Tenant Isolation Bypass in BerriAI LiteLLM Semantic Cache","url":"https://feed.craftedsignal.io/briefs/2026-09-litellm-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - LiteLLM (\u003c 1.101.0-Rc.1)","version":"https://jsonfeed.org/version/1.1"}