Vulnerabilidades en berriai

41 resultados
Análisis Vexday

A Berriai apresenta um portfólio modesto de 15 vulnerabilidades, com 3 classificadas como críticas, porém nenhuma está sob ataque ativo (KEV). A fraqueza dominante é CWE-94 (Improper Control of Generation of Code), indicando riscos de execução de código não autorizado no design do produto. A ausência de divulgações recentes sugere que o risco atual é estável e não representa uma janela de exposição aguda.

CVE-2026-35030CRITICALLiteLLM has an authentication bypass via OIDC userinfo cache key collisionEPSS 0.6%CVE-2024-4888MEDIUMArbitrary File Deletion in BerriAI/litellmEPSS 0.6%CVE-2026-59820MEDIUMLiteLLM: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')EPSS 0.6%CVE-2026-59819LOWLiteLLM: Local file read via request-supplied OIDC file referencesEPSS 0.6%CVE-2026-12796MEDIUMBerriAI litellm SSO Authentication Flow ui_sso.py get_redirect_response_from_openid session expirationEPSS 0.6%CVE-2026-12770MEDIUMBerriAI litellm Admin Key key_management_endpoints.py improper authorizationEPSS 0.6%CVE-2024-4890MEDIUMBlind SQL Injection in berriai/litellmEPSS 0.6%CVE-2024-10188HIGHDenial of Service in BerriAI/litellmEPSS 0.6%CVE-2025-0330HIGHExposure of Sensitive Information in berriai/litellmEPSS 0.6%CVE-2026-59823MEDIUMLiteLLM: Server-side request forgery via the `user_config` request parameter in LiteLLM ProxyEPSS 0.4%CVE-2026-12771LOWBerriAI litellm M2M JWT user_api_key_auth.py improper authorizationEPSS 0.4%CVE-2024-5225MEDIUMSQL Injection in berriai/litellmEPSS 0.4%CVE-2026-12799MEDIUMBerriAI litellm Incomplete Fix CVE-2025-0628 internal_user_endpoints.py ui_view_users improper authorizationEPSS 0.4%CVE-2024-5710MEDIUMImproper Access Control in Team Management in berriai/litellmEPSS 0.4%CVE-2026-12798MEDIUMBerriAI litellm MCP OpenAPI Spec Loader openapi_to_mcp_generator.py load_openapi_spec_async server-side request forgeryEPSS 0.4%CVE-2026-12797MEDIUMBerriAI litellm Completions banned_keywords.py async_pre_call_hook authorizationEPSS 0.4%CVE-2026-12774MEDIUMBerriAI litellm MCP Server Connection Testing rest_endpoints.py _execute_with_mcp_client server-side request forgeryEPSS 0.4%CVE-2026-12772MEDIUMBerriAI litellm PROXY_ADMIN database API Key Generator login_utils.py authenticate_user session expirationEPSS 0.4%CVE-2026-42203HIGHLiteLLM: Server-Side Template Injection in /prompts/test endpointEPSS 0.4%CVE-2025-0628HIGHImproper Authorization in BerriAI/litellmEPSS 0.3%