Vulnerability Intelligence Report
Improper Authorization in BerriAI/litellm
CVE-2025-0628
An improper authorization vulnerability exists in the main-latest version of BerriAI/litellm. When a user with the role 'internal_user_viewer' logs into the application, they are provided with an overly privileged API key. This key can be used to access all the admin functionality of the application, including endpoints such as '/users/list' and '/users/get_users'. This vulnerability allows for privilege escalation within the application, enabling any account to become a PROXY ADMIN.
No Active Exploit Signals
CVSS Base Score
8.1
HIGH
Exploitability:2.9
Impact Score:5.2
EPSS Probability:0.32%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-266 ↗CWE-266 Incorrect Privilege Assignment
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| berriai | berriai/litellm | unspecified < v1.61.15-nightly (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
0.315%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Protect AI (formerly huntr.dev) · Bug Bounty Provider · USA |
| Reserved | 2025-01-21T19:10:36 |
| Published | 2025-03-20T10:10:45 |
| Last Updated | 2025-10-15T12:50:05 |
Community Chatter & Buzz