Vulnerabilities in berriai

42 results
Vexday analysis

A Berriai apresenta um portfólio modesto de 15 vulnerabilidades, com 3 classificadas como críticas, porém nenhuma está sob ataque ativo (KEV). A fraqueza dominante é CWE-94 (Improper Control of Generation of Code), indicando riscos de execução de código não autorizado no design do produto. A ausência de divulgações recentes sugere que o risco atual é estável e não representa uma janela de exposição aguda.

CVE-2024-6587HIGHSSRF in berriai/litellmEPSS 35.3%CVE-2026-42271HIGHLiteLLM: Authenticated command execution via MCP stdio test endpointsEPSS 12.8%KEVCVE-2026-42208CRITICALLiteLLM: SQL injection in Proxy API key verificationEPSS 5.8%KEVCVE-2026-35029HIGHLiteLLM affected by privilege escalation via unrestricted proxy configuration endpointEPSS 4.0%CVE-2026-40217HIGHLiteLLM through 2026-04-08 allows remote attackers to execute arbitrary code via bytecode rewriting at the /guardrails/test_custom_code URI.EPSS 3.4%CVE-2026-33634CRITICALTrivy ecosystem supply chain briefly compromisedEPSS 1.7%KEVCVE-2024-6825HIGHRemote Code Execution in BerriAI/litellmEPSS 1.7%CVE-2026-47101HIGHLiteLLM < 1.83.14 Privilege Escalation via API Key GenerationEPSS 1.3%CVE-2024-2952CRITICALServer-Side Template Injection in BerriAI/litellmEPSS 1.3%CVE-2026-12773MEDIUMBerriAI litellm MCP Proxy user_api_key_auth_mcp.py UserAPIKeyAuth improper authenticationEPSS 1.0%CVE-2026-59821LOWLiteLLM: Custom Code Guardrails production endpoints bypass code safety checksEPSS 0.9%CVE-2024-4264CRITICALRemote Code Execution in berriai/litellmEPSS 0.9%CVE-2024-5751CRITICALRemote Code Execution in BerriAI/litellmEPSS 0.9%CVE-2026-35030CRITICALLiteLLM has an authentication bypass via OIDC userinfo cache key collisionEPSS 0.9%CVE-2024-4889HIGHCode Injection in berriai/litellmEPSS 0.9%CVE-2024-8984HIGHDenial of Service (DoS) in berriai/litellmEPSS 0.8%CVE-2026-59822HIGHLiteLLM: MCP Authentication Bypass via OAuth2 Passthrough FallbackEPSS 0.8%KEVCVE-2026-47102HIGHLiteLLM < 1.83.10 Privilege Escalation via User UpdateEPSS 0.8%CVE-2026-49468CRITICALLiteLLM: Authentication Bypass via Host Header InjectionEPSS 0.8%CVE-2026-12795MEDIUMBerriAI litellm SSO Debug Flow ui_sso.py json.dumps missing authenticationEPSS 0.8%