CVE-2025-0628

HIGH

BerriAI/litellm - Privilege Escalation

Title source: llm
STIX 2.1

Description

An improper authorization vulnerability exists in the main-latest version of BerriAI/litellm. When a user with the role 'internal_user_viewer' logs into the application, they are provided with an overly privileged API key. This key can be used to access all the admin functionality of the application, including endpoints such as '/users/list' and '/users/get_users'. This vulnerability allows for privilege escalation within the application, enabling any account to become a PROXY ADMIN.

Scores

CVSS v3 8.1
EPSS 0.0027
EPSS Percentile 50.7%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-266
Status published
Products (2)
berriai/berriai/litellm unspecified - v1.61.15-nightly
pypi/litellm 0 - 1.61.15PyPI
Published Mar 20, 2025
Tracked Since Feb 18, 2026