Intel

AIKIDO-2026-775316

litellm is vulnerable to Privilege Escalation

Privilege EscalationGHSA-7hp6-4w63-5g45 Published Yesterday

99

Critical Risk

This Affects:

PYTHONlitellm
1.91.0 - 1.100.3
Fixed in 1.100.4
1.101.0 - 1.101.2
Fixed in 1.101.3
1.102.0 - 1.102.1
Fixed in 1.102.2
1.103.0 - 1.103.0
Fixed in 1.103.1
Are you affected? Scan for Free

TL;DR

LiteLLM's proxy encrypts both secrets stored in request metadata and UI/CLI session tokens with the same AES-GCM key and helper, with no domain separation between the two uses. An internal user can request a new virtual key with a metadata field holding a forged proxy_admin session payload as the "secret" value, then present the proxy's own encrypted response back as a bearer token. The proxy decrypts that token and accepts it as an admin session, so a low privileged user can escalate to proxy_admin and run arbitrary commands through the MCP stdio endpoint. The fix binds session token encryption to a distinct, prefix bound key context so a stored secret can no longer be replayed as a session token.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

litellm is vulnerable to Privilege Escalation in versions 1.91.0 - 1.100.3, 1.101.0 - 1.101.2, 1.102.0 - 1.102.1 and 1.103.0 - 1.103.0.

How to fix this

Upgrade the litellm library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform