Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

BerriAI — Vulnerabilities & Security Advisories 38

Browse all 38 CVE security advisories affecting BerriAI. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Berriai develops AI-powered code analysis tools to help developers identify and fix security vulnerabilities in their applications. Historically, the platform has been associated with vulnerabilities including remote code execution, cross-site scripting, and privilege escalation, with 18 CVEs documented to date. Security researchers have identified issues related to improper input validation and insecure default configurations, though no major public security incidents have been reported. The tool's integration into development workflows creates potential attack surfaces if not properly configured, emphasizing the need for secure implementation practices beyond the tool's own security posture.

Top products by BerriAI: litellm berriai/litellm
CVE IDTitleCVSSSeverityPublished
CVE-2026-59819 LiteLLM: Local file read via request-supplied OIDC file references — litellmCWE-73--2026-07-08
CVE-2026-59822 LiteLLM: MCP Authentication Bypass via OAuth2 Passthrough Fallback — litellmCWE-287--2026-07-08
CVE-2026-59820 LiteLLM: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') — litellmCWE-22--2026-07-08
CVE-2026-59821 LiteLLM: Custom Code Guardrails production endpoints bypass code safety checks — litellmCWE-94--2026-07-08
CVE-2026-49468 LiteLLM: Authentication Bypass via Host Header Injection — litellmCWE-290--2026-06-22
CVE-2026-12799 BerriAI litellm Incomplete Fix CVE-2025-0628 internal_user_endpoints.py ui_view_users improper authorization — litellmCWE-285 4.3 Medium2026-06-21
CVE-2026-12798 BerriAI litellm MCP OpenAPI Spec Loader openapi_to_mcp_generator.py load_openapi_spec_async server-side request forgery — litellmCWE-918 6.3 Medium2026-06-21
CVE-2026-12797 BerriAI litellm Completions banned_keywords.py async_pre_call_hook authorization — litellmCWE-863 6.3 Medium2026-06-21
CVE-2026-12796 BerriAI litellm SSO Authentication Flow ui_sso.py get_redirect_response_from_openid session expiration — litellmCWE-613 6.3 Medium2026-06-21
CVE-2026-12795 BerriAI litellm SSO Debug Flow ui_sso.py json.dumps missing authentication — litellmCWE-306 7.3 High2026-06-21
CVE-2026-12774 BerriAI litellm MCP Server Connection Testing rest_endpoints.py _execute_with_mcp_client server-side request forgery — litellmCWE-918 6.3 Medium2026-06-21
CVE-2026-12773 BerriAI litellm MCP Proxy user_api_key_auth_mcp.py UserAPIKeyAuth improper authentication — litellmCWE-287 7.3 High2026-06-21
CVE-2026-12772 BerriAI litellm PROXY_ADMIN database API Key Generator login_utils.py authenticate_user session expiration — litellmCWE-613 6.3 Medium2026-06-21
CVE-2026-12771 BerriAI litellm M2M JWT user_api_key_auth.py improper authorization — litellmCWE-285 5.0 Medium2026-06-21
CVE-2026-12770 BerriAI litellm Admin Key key_management_endpoints.py improper authorization — litellmCWE-285 5.4 Medium2026-06-21
CVE-2026-47102 LiteLLM < 1.83.10 Privilege Escalation via User Update — litellmCWE-863 8.8 High2026-05-21
CVE-2026-47101 LiteLLM < 1.83.14 Privilege Escalation via API Key Generation — litellmCWE-863 8.8 High2026-05-21
CVE-2026-42208 LiteLLM: SQL injection in Proxy API key verification — litellmCWE-89 9.1AICriticalAI2026-05-08
CVE-2026-42203 LiteLLM: Server-Side Template Injection in /prompts/test endpoint — litellmCWE-1336 9.6AICriticalAI2026-05-08
CVE-2026-42271 LiteLLM: Authenticated command execution via MCP stdio test endpoints — litellmCWE-77 9.8AICriticalAI2026-05-08
CVE-2026-40217 LiteLLM 安全漏洞 — LiteLLMCWE-420 8.8 High2026-04-10
CVE-2026-35030 LiteLLM has an authentication bypass via OIDC userinfo cache key collision — litellmCWE-287 6.5AIMediumAI2026-04-06
CVE-2026-35029 LiteLLM affected by privilege escalation via unrestricted proxy configuration endpoint — litellmCWE-863 8.8AIHighAI2026-04-06
CVE-2024-6825 Remote Code Execution in BerriAI/litellm — berriai/litellmCWE-94 9.8 -2025-03-20
CVE-2024-10188 Denial of Service in BerriAI/litellm — berriai/litellmCWE-400 7.5 -2025-03-20
CVE-2025-0628 Improper Authorization in BerriAI/litellm — berriai/litellmCWE-266 8.8 -2025-03-20
CVE-2025-0330 Exposure of Sensitive Information in berriai/litellm — berriai/litellmCWE-1230 7.5 -2025-03-20
CVE-2024-9606 Improper Output Neutralization for Logs in berriai/litellm — berriai/litellmCWE-117 7.5 -2025-03-20
CVE-2024-8984 Denial of Service (DoS) in berriai/litellm — berriai/litellmCWE-770 7.5 -2025-03-20
CVE-2024-6587 SSRF in berriai/litellm — berriai/litellmCWE-918 8.1AIHighAI2024-09-13

This page lists every published CVE security advisory associated with BerriAI. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.