Intel

AIKIDO-2025-10076

litellm is vulnerable to Authorization Bypass

Authorization Bypass Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.

40

Medium Risk

This Affects:

pythonlitellm
1.56.2 - 1.60.3
Fixed in 1.60.4

TL;DR

Affected versions of this package are vulnerable to an authorization bypass, allowing a user to modify another user's keys without the necessary privileges. This flaw enables unauthorized access to sensitive data or actions, potentially leading to privilege escalation or data integrity issues.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

litellm is vulnerable to Authorization Bypass in versions 1.56.2 - 1.60.3.

How to fix this

Upgrade the litellm library to the patch version.