Vulnerabilidades em berriai

39 resultados
Análise Vexday

A Berriai apresenta um portfólio modesto de 15 vulnerabilidades, com 3 classificadas como críticas, porém nenhuma está sob ataque ativo (KEV). A fraqueza dominante é CWE-94 (Improper Control of Generation of Code), indicando riscos de execução de código não autorizado no design do produto. A ausência de divulgações recentes sugere que o risco atual é estável e não representa uma janela de exposição aguda.

CVE-2025-0330HIGHExposure of Sensitive Information in berriai/litellmEPSS 0.5%CVE-2026-12795MEDIUMBerriAI litellm SSO Debug Flow ui_sso.py json.dumps missing authenticationEPSS 0.5%CVE-2026-35030CRITICALLiteLLM has an authentication bypass via OIDC userinfo cache key collisionEPSS 0.5%CVE-2024-5225MEDIUMSQL Injection in berriai/litellmEPSS 0.4%CVE-2024-5710MEDIUMImproper Access Control in Team Management in berriai/litellmEPSS 0.4%CVE-2026-12797MEDIUMBerriAI litellm Completions banned_keywords.py async_pre_call_hook authorizationEPSS 0.4%CVE-2026-42203HIGHLiteLLM: Server-Side Template Injection in /prompts/test endpointEPSS 0.4%CVE-2026-12796MEDIUMBerriAI litellm SSO Authentication Flow ui_sso.py get_redirect_response_from_openid session expirationEPSS 0.4%CVE-2026-59821LOWLiteLLM: Custom Code Guardrails production endpoints bypass code safety checksEPSS 0.4%CVE-2026-12770MEDIUMBerriAI litellm Admin Key key_management_endpoints.py improper authorizationEPSS 0.3%CVE-2025-0628HIGHImproper Authorization in BerriAI/litellmEPSS 0.3%CVE-2026-59820MEDIUMLiteLLM: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')EPSS 0.3%CVE-2026-59822HIGHLiteLLM: MCP Authentication Bypass via OAuth2 Passthrough FallbackEPSS 0.3%CVE-2026-12771LOWBerriAI litellm M2M JWT user_api_key_auth.py improper authorizationEPSS 0.3%CVE-2026-12799MEDIUMBerriAI litellm Incomplete Fix CVE-2025-0628 internal_user_endpoints.py ui_view_users improper authorizationEPSS 0.3%CVE-2026-12798MEDIUMBerriAI litellm MCP OpenAPI Spec Loader openapi_to_mcp_generator.py load_openapi_spec_async server-side request forgeryEPSS 0.3%CVE-2026-12774MEDIUMBerriAI litellm MCP Server Connection Testing rest_endpoints.py _execute_with_mcp_client server-side request forgeryEPSS 0.3%CVE-2026-12772MEDIUMBerriAI litellm PROXY_ADMIN database API Key Generator login_utils.py authenticate_user session expirationEPSS 0.3%CVE-2026-59819LOWLiteLLM: Local file read via request-supplied OIDC file referencesEPSS 0.3%