PyPI package intelligence

litellm Known Exploited Vulnerabilities

Track evidence-backed exploitation affecting the PyPI package litellm, including the gap beyond CISA KEV, confidence assessments, and sensor observations.

Total KEVs
4
Known exploited vulnerabilities affecting litellm
In CISA KEV
3
Records also listed in the official catalog
Beyond CISA KEV
1
Additional exploited vulnerabilities absent from CISA KEV
Sensor Observed
0
litellm KEVs with sensor-observed exploitation activity

Review litellm exploitation against the versions you run

One of the four exploited litellm vulnerabilities tracked here are not in CISA KEV.

75%
Covered by CISA
25%
Beyond CISA

Attested litellm vulnerabilities

4 known exploited vulnerabilities affecting this package.

Vulnerability CISA KEV Added
CVE-2026-59822

LiteLLM: MCP Authentication Bypass via OAuth2 Passthrough Fallback

In CISA 02 Sep 2026
CVE-2026-42271

LiteLLM: Authenticated command execution via MCP stdio test endpoints

In CISA 08 Jun 2026
CVE-2026-42208

LiteLLM: SQL injection in Proxy API key verification

In CISA 01 Jun 2026
CVE-2024-6587

SSRF in berriai/litellm

Beyond CISA 13 Sep 2024

Recurring weakness patterns

Improper Authentication, Missing Authentication for Critical Function, and Improper Neutralization of Special Elements used in a Command ('Command Injection') account for mapped occurrences across this litellm KEV portfolio.

Browse all KEVs →