Impact
BerriAI litellm, up to version 1.82.2, contains a flaw in the load_openapi_spec_async function used by the MCP OpenAPI Spec Loader. The function accepts a spec_path argument without adequate validation, enabling an attacker to supply a target URL and force the server to perform an outbound HTTP request. This server‑side request forgery can be used to reach internal or external systems, exfiltrate data, or facilitate further attacks such as credential harvesting. The vulnerability does not grant direct code execution, but it can be leveraged to discover exposed services or trigger downstream exploits via forged requests.
Affected Systems
The affected component is BerriAI litellm, versions up to 1.82.2. No specific patch version is listed, but the vulnerability pertains to all releases of that product without an updated fix. Vendors and users should verify whether a newer release is available and apply it.
Risk and Exploitability
The CVSS score of 5.3 represents moderate severity. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. Since the flaw can be triggered remotely by supplying a crafted spec_path, the attack vector is external. Publicly available proof‑of‑concept code exists, suggesting that exploitation is feasible. Overall, the risk is moderate, with potential for significant impact if the server is used as a pivot point in a larger attack chain.
OpenCVE Enrichment