BerriAI vendor intelligence
BerriAI Known Exploited Vulnerabilities
Track evidence-backed exploitation affecting BerriAI products, including the gap beyond CISA KEV, confidence assessments, sensor observations, and practical response context.
- Total KEVs
- 5
- Known exploited vulnerabilities affecting BerriAI products
- In CISA KEV
- 4
- Records also listed in the official catalog
- Beyond CISA KEV
- 1
- Additional exploited vulnerabilities absent from CISA KEV
- Sensor Observed
- 0
- BerriAI KEVs with sensor-observed exploitation activity
The catalog gap matters for BerriAI exposure
One of the five exploited BerriAI vulnerabilities tracked here are not in CISA KEV. Teams relying on the official catalog alone would miss one-fifth of this vendor portfolio.
- 80%
- Covered by CISA
- 20%
- Beyond CISA
- 3
- Product families
Attested BerriAI vulnerabilities
5 known exploited vulnerabilities in this exploited-vulnerability portfolio. Search, then narrow it to official CISA coverage or the additional records Previdian tracks beyond the catalog.
How exploitation is verified| CVE / description | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2026-59822
LiteLLM: MCP Authentication Bypass via OAuth2 Passthrough Fallback |
litellm | Confirmed | In CISA | 02 Sep 2026 |
|
CVE-2026-42271
LiteLLM: Authenticated command execution via MCP stdio test endpoints |
litellm | Confirmed | In CISA | 08 Jun 2026 |
|
CVE-2026-42208
LiteLLM: SQL injection in Proxy API key verification |
litellm | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2026-33634
Trivy ecosystem supply chain briefly compromised |
setup-trivy, trivy-action, trivy, LiteLLM, telnyx | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2024-6587
SSRF in berriai/litellm |
berriai/litellm | High | Beyond CISA | 13 Sep 2024 |
No BerriAI vulnerabilities match this search or filter.
Showing 5 of 5 on this page (5 BerriAI known exploited vulnerabilities).
Recurring weakness patterns
Authentication, missing authentication for critical function, and embedded malicious code account for three mapped occurrences across this BerriAI KEV portfolio.
CWE-287
Improper Authentication
CWE-306
Missing Authentication for Critical Function
CWE-506
Embedded Malicious Code
CWE-77
Improper Neutralization of Special Elements used in a Command ('Command Injection')
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CWE-918
Server-Side Request Forgery (SSRF)