litellm is vulnerable to Incorrect Authorization
71
High Risk
Affected versions of this package are vulnerable to incorrect authorization because _check_proxy_admin_viewer_access fails to enforce role boundaries. As a result, users granted the PROXY_ADMIN_VIEW_ONLY role—who should have read-only access—can perform privileged actions (for example, POST /key/generate or POST /key/update) by sending crafted requests, allowing them to modify credentials and other sensitive data.
You are affected if you are using a version that falls within the vulnerable range.
litellm is vulnerable to Incorrect Authorization in versions 1.74.6 - 1.77.0.
Upgrade the litellm library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant