A AegiFlow
MEDIUMCVSS 5.5EPSS 1.0%

CVE-2026-12773

LiteLLM: MCP Proxy Has Improper Authentication

Published
2026-06-21
Modified
2026-09-10
EPSS percentile
61%
Aliases
GHSA-4jcj-7x88-m979
Sources
github-advisory

Summary

A weakness has been identified in BerriAI litellm up to 1.59.8. Affected is the function UserAPIKeyAuth of the file litellm/proxy/_experimental/mcp_server/auth/user_api_key_auth_mcp.py of the component MCP Proxy. Executing a manipulation can lead to improper authentication. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure.

Affected packages

EcosystemPackageAffected versionsFixed versions
PyPIlitellm1.84.0

Remediation: Upgrade to 1.84.0 or later.

References

Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.

EPSS scores provided by the FIRST.org Exploit Prediction Scoring System.