Impact
LiteLLM contains a /config/update endpoint that accepts changes without checking whether the caller holds administrative privileges. This lack of authorization enforcement is a CWE‑425 weakness and allows an authenticated user to alter proxy settings, override environment variables, and register custom pass‑through handlers pointing to attacker‑controlled Python code. Such manipulation can trigger remote code execution, enable reading of arbitrary server files by setting UI_LOGO_PATH and retrieving the image, and facilitate credential take‑over by changing UI_USERNAME and UI_PASSWORD. The vulnerability is therefore a high‑severity flaw that exposes the entire LiteLLM instance to compromise once authentication is achieved.
Affected Systems
The vendor BerriAI provides LiteLLM, and all deployments of LiteLLM older than version 1.83.0 that expose the /config/update endpoint are vulnerable. No additional vendors or downstream distributions are listed, so the impact is confined to the primary product and its legacy versions.
Risk and Exploitability
The CVSS score of 8.7 indicates high severity, and the EPSS score of 4% signals a significant likelihood that attackers will exploit the flaw in the wild. The vulnerability is not listed in the CISA KEV catalog, suggesting it has not yet been observed in large‑scale exploitation, but its high probability and the severity of potential impact warrant immediate attention. An attacker must already be authenticated to the system, which could be achieved through legitimate use or credential compromise. Once authenticated, the attacker can issue the vulnerable request from any network location having access to LiteLLM, making the attack vector effectively remote and contingent only on prior access. The conditions for exploitation are minimal—authentication and endpoint reachability—making this a highly actionable threat.
OpenCVE Enrichment
Github GHSA