Impact
LiteLLM's authentication flow allows an attacker who possesses a valid JSON Web Token issued by the configured identity provider to log in as any existing user. The vulnerability stems from an email-based fallback lookup that does not validate the email_verified claim. Attackers can craft a token containing an unverified email address that matches a victim's account, thereby inheriting the victim's role—including proxy_admin privileges. Once authenticated, the attacker can permanently overwrite the victim’s stored identity binding, ensuring continued unauthorized access to administrative endpoints such as API key management and user configuration.
Affected Systems
BerriAI:LiteLLm is the affected vendor/product. Specific affected versions are not supplied, but any deployment of LiteLLM that uses the default JWT authentication configuration is potentially vulnerable.
Risk and Exploitability
The CVSS score of 7.6 signifies a high severity, with a large impact if exploited. EPSS is not available, so the current probability of exploitation cannot be quantified; the vulnerability is not listed in the CISA KEV catalog. The attack requires an attacker to already possess a valid JWT, but an attacker can guess or discover a victim’s email address through publicly available information or enumeration. Once the email is mirrored in the forged token, the authentication bypass occurs and the attacker can credibly impersonate the victim and modify stored identities, giving them permanent administrative access.
OpenCVE Enrichment