PT-2025-12318 · Unknown · Berriai/Litellm

Published

2025-03-20

·

Updated

2025-03-23

·

CVE-2025-0628

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions BerriAI/litellm version main-latest
Description The issue is related to improper authorization. When a user with the role internal user viewer logs into the application, they are provided with an overly privileged API key. This key allows access to all admin functionality, including endpoints such as "/users/list" and "/users/get users". The vulnerability enables privilege escalation within the application, allowing any account to become a proxy admin.
Recommendations For BerriAI/litellm version main-latest, consider restricting access to the /users/list and /users/get users endpoints until a fix is available. As a temporary workaround, review and limit the privileges assigned to the internal user viewer role to prevent unauthorized access to admin functionality.

Fix

LPE

Improper Authorization

Incorrect Privilege Assignment

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-0628
GHSA-FJCF-3J3R-78RP

Affected Products

Berriai/Litellm