GHSA-j37q-q7p9-vpwmMediumCVSS 7.3

LiteLLM: SSO Debug Flow Has Improper Authentication

Published
June 21, 2026
Last Modified
September 10, 2026

🔗 CVE IDs covered (1)

📋 Description

A vulnerability was determined in BerriAI litellm up to 1.82.2. This affects the function json.dumps of the file litellm/proxy/management_endpoints/ui_sso.py of the component SSO Debug Flow. Executing a manipulation can lead to missing authentication. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure.

🎯 Affected products1

  • pip/litellm:<= 1.82.2

🔗 References (7)