LiteLLM GHSA-7hp6-4w63-5g45 (30 Sep): salt-key reuse → internal_user to proxy_admin + RCE (CVSS 9.9)
BerriAI LiteLLM GitHub security advisory GHSA-7hp6-4w63-5g45 (published 30 September 2026; Critical CVSS 3.1 9.9; CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H) — authenticated internal_user can escalate to proxy_admin and execute arbitrary commands. Root cause: one encryption key seals secrets at rest and mints session tokens. Attacker requests a new API key with crafted metadata containing a forged admin credential as the “secret”; proxy encrypts and returns it; presenting that value as a bearer token decrypts to a trusted admin identity, including MCP stdio command execution. Default-config exploitable on versions later than 1.91.0; 1.87.0–1.90.x only if EXPERIMENTAL_UI_LOGIN=true. Patched: 1.100.4, 1.101.3, 1.102.2, 1.103.1, 1.104.0rc2 (per advisory ranges). Interim: EXPERIMENTAL_UI_LOGIN=false (disables vulnerable path; breaks CLI SSO / Claude Code gateway login). Credit: Hoa X. Nguyen (OPSWAT Unit 515). Category tech (AI gateway stack). Distinct from desk litellm-default-sk1234-20260909 (default master key exposure). Primary: GitHub advisory.
- Product
- BerriAI LiteLLM (pip / LLM proxy gateway)
- Versions
- Affected: >=1.91.0 default config until patched trains; 1.87.0–1.90.x if EXPERIMENTAL_UI_LOGIN=true. Fixed: 1.100.4 / 1.101.3 / 1.102.2 / 1.103.1 / 1.104.0rc2.
- CVSS
- (CVSS 3.1 Critical)
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H - Exploited in Australia?
- unknown
- Patch to
- Upgrade to patched LiteLLM train (1.100.4+ / matching branch fix); or set EXPERIMENTAL_UI_LOGIN=false until upgrade.
Primary: GitHub — LiteLLM GHSA-7hp6-4w63-5g45 (30 Sep 2026) · Vendor: BerriAI LiteLLM security advisories
