{"schemaVersion":"ki-abhaengigkeitsatlas/v1","dataset":"german-public-sector-ai-dependency-atlas","parserVersion":"1","generatedAt":"2026-07-20T14:37:29.537Z","trackingSince":"2026-07-18T21:20:30.334Z","source":{"codeRadar":{"dataset":"german-public-sector-ai-code-radar","generatedAt":"2026-07-20T14:36:19.763Z","parserVersion":"3","url":"https://i6eal.de/tools/ki-code-radar/"},"openCode":{"label":"openCode GitLab","url":"https://gitlab.opencode.de/"},"depsDev":{"label":"deps.dev API v3","url":"https://docs.deps.dev/api/v3/"},"osv":{"label":"OSV API","url":"https://google.github.io/osv.dev/api/"},"spdx":{"label":"SPDX License List","url":"https://spdx.org/licenses/","version":"3.28.0","releaseDate":"2026-02-20T00:00:00Z"}},"coverage":{"repositoryCount":30,"completeTreeCount":29,"incompleteTreeCount":1,"lockfileRepositoryCount":17,"sbomRepositoryCount":4,"artifactRepositoryCount":20,"resolvedRepositoryCount":29,"resolvedArtifactRepositoryCount":20,"dependencyFileCount":33,"parsedFileCount":32,"parseErrorCount":1,"unsupportedFileCount":0,"evaluatedVersionCount":4205,"metadataResolvedCount":4191,"metadataNotFoundCount":14,"osvEvaluatedVersionCount":4205,"codeRadarRepositoryCount":30},"methodology":{"componentParserSchemaVersion":"ki-dependency-atlas-components/v1","candidateBoundary":"repositories_with_exact_ai_code_evidence","resolvedVersionBoundary":"exact_lockfile_or_sbom_component_or_exact_double_equals_manifest_pin","manifestRangesResolved":false,"latestVersionSubstitution":false,"containerTagsVulnerabilityChecked":false,"osvClaim":"osv_matched_observed_resolved_package_version_at_collection_time","depsDevLicenseSemantics":"spdx_expressions_as_reported_without_inferred_compatibility","providerSemantics":"package_interface_presence_not_api_configuration_procurement_or_use","generativeAiUsed":false,"scoreUsed":false,"treeEntryCeiling":2500,"fileByteCeiling":5242880,"uniqueVersionCeiling":5000,"observedFormats":["package-lock.json / npm-shrinkwrap.json","uv.lock","poetry.lock","Pipfile.lock","CycloneDX JSON","SPDX JSON or YAML","exact == manifest pins"]},"summary":{"repositoryCount":30,"packageCount":2831,"aiPackageCount":41,"resolvedComponentCount":7181,"resolvedVersionCount":4205,"providerExposureRepositoryCount":7,"licenseExpressionCount":57,"knownLicensePackageCount":2796,"unknownLicensePackageCount":35,"advisoryCount":572,"matchedAdvisoryRepositoryCount":25,"topPackage":{"id":"package:pypi:openai","slug":"openai-0dd26ac5","label":"OpenAI SDK","repositoryCount":18,"repositoryShare":0.6}},"kind":"paket","entity":{"id":"package:pypi:litellm","slug":"litellm-e00b5c8b","identity":"pypi:litellm","ecosystem":"pypi","name":"litellm","label":"LiteLLM","category":"model-api","aiRelevant":true,"provider":null,"repositoryCount":4,"occurrenceCount":4,"directRepositoryCount":1,"versionCount":4,"licenseExpressions":["MIT"],"advisoryIds":["GHSA-4xpc-pv4p-pm3w","GHSA-53mr-6c8q-9789","GHSA-69x8-hrgq-fjj8","GHSA-fh2c-86xm-pm2x","GHSA-fjcf-3j3r-78rp","GHSA-jjhc-v7c2-5hh6","GHSA-qrc4-49gv-mv9m","GHSA-wpfp-gwwc-vwq6"],"advisoryCount":8,"verifiedAttestation":false,"repositories":[{"id":"opencode:7781","slug":"opencode-7781","name":"kiva-llm-gateway","pathWithNamespace":"baden-wuerttemberg/innenministerium/kiva.platform/kiva-llm-gateway","versions":["1.67.4.dev1"],"evidenceCount":1},{"id":"opencode:5530","slug":"opencode-5530","name":"GSA Extraction","pathWithNamespace":"uba-ki-lab/gsa-extraction","versions":["1.73.6.post1"],"evidenceCount":1},{"id":"opencode:5012","slug":"opencode-5012","name":"LLM Testframework","pathWithNamespace":"uba-ki-lab/llm-testframework","versions":["1.68.0"],"evidenceCount":1},{"id":"opencode:4112","slug":"opencode-4112","name":"Objection management","pathWithNamespace":"uba-ki-lab/objection-management","versions":["1.53.7"],"evidenceCount":1}],"versions":[{"version":"1.53.7","repositoryCount":1,"occurrenceCount":1,"ageDays":592,"advisoryIds":["GHSA-4xpc-pv4p-pm3w","GHSA-53mr-6c8q-9789","GHSA-69x8-hrgq-fjj8","GHSA-fh2c-86xm-pm2x","GHSA-fjcf-3j3r-78rp","GHSA-jjhc-v7c2-5hh6","GHSA-qrc4-49gv-mv9m","GHSA-wpfp-gwwc-vwq6"],"metadata":{"state":"resolved","checkedAt":"2026-07-20T03:19:50.101Z","publishedAt":"2024-12-05T08:32:02Z","deprecated":false,"deprecatedReason":null,"licenses":["MIT"],"advisoryIds":["GHSA-4xpc-pv4p-pm3w","GHSA-53mr-6c8q-9789","GHSA-69x8-hrgq-fjj8","GHSA-fh2c-86xm-pm2x","GHSA-fjcf-3j3r-78rp","GHSA-jjhc-v7c2-5hh6","GHSA-qrc4-49gv-mv9m","GHSA-wpfp-gwwc-vwq6","PYSEC-2026-1545","PYSEC-2026-1546","PYSEC-2026-2597","PYSEC-2026-2598","PYSEC-2026-2600","PYSEC-2026-388","PYSEC-2026-390"],"links":[{"label":"SOURCE_REPO","url":"https://github.com/BerriAI/litellm"},{"label":"DOCUMENTATION","url":"https://docs.litellm.ai/"},{"label":"HOMEPAGE","url":"https://litellm.ai/"}],"relatedProjects":[{"id":"github.com/berriai/litellm","relationType":"SOURCE_REPO","relationProvenance":"UNVERIFIED_METADATA"}],"attestations":[],"verifiedAttestation":false,"projectStatus":"active"}},{"version":"1.67.4.dev1","repositoryCount":1,"occurrenceCount":1,"ageDays":449,"advisoryIds":["GHSA-4xpc-pv4p-pm3w","GHSA-53mr-6c8q-9789","GHSA-69x8-hrgq-fjj8","GHSA-jjhc-v7c2-5hh6","GHSA-qrc4-49gv-mv9m","GHSA-wpfp-gwwc-vwq6"],"metadata":{"state":"resolved","checkedAt":"2026-07-20T03:19:50.101Z","publishedAt":"2025-04-27T02:36:07Z","deprecated":false,"deprecatedReason":null,"licenses":["MIT"],"advisoryIds":["GHSA-4xpc-pv4p-pm3w","GHSA-53mr-6c8q-9789","GHSA-69x8-hrgq-fjj8","GHSA-jjhc-v7c2-5hh6","GHSA-qrc4-49gv-mv9m","GHSA-wpfp-gwwc-vwq6","PYSEC-2026-2597","PYSEC-2026-2598","PYSEC-2026-2600","PYSEC-2026-388","PYSEC-2026-390"],"links":[{"label":"HOMEPAGE","url":"https://litellm.ai/"},{"label":"SOURCE_REPO","url":"https://github.com/BerriAI/litellm"},{"label":"DOCUMENTATION","url":"https://docs.litellm.ai/"}],"relatedProjects":[{"id":"github.com/berriai/litellm","relationType":"SOURCE_REPO","relationProvenance":"UNVERIFIED_METADATA"}],"attestations":[],"verifiedAttestation":false,"projectStatus":"active"}},{"version":"1.68.0","repositoryCount":1,"occurrenceCount":1,"ageDays":442,"advisoryIds":["GHSA-4xpc-pv4p-pm3w","GHSA-53mr-6c8q-9789","GHSA-69x8-hrgq-fjj8","GHSA-jjhc-v7c2-5hh6","GHSA-qrc4-49gv-mv9m","GHSA-wpfp-gwwc-vwq6"],"metadata":{"state":"resolved","checkedAt":"2026-07-20T03:19:50.101Z","publishedAt":"2025-05-04T05:41:44Z","deprecated":false,"deprecatedReason":null,"licenses":["MIT"],"advisoryIds":["GHSA-4xpc-pv4p-pm3w","GHSA-53mr-6c8q-9789","GHSA-69x8-hrgq-fjj8","GHSA-jjhc-v7c2-5hh6","GHSA-qrc4-49gv-mv9m","GHSA-wpfp-gwwc-vwq6","PYSEC-2026-2597","PYSEC-2026-2598","PYSEC-2026-2600","PYSEC-2026-388","PYSEC-2026-390"],"links":[{"label":"SOURCE_REPO","url":"https://github.com/BerriAI/litellm"},{"label":"DOCUMENTATION","url":"https://docs.litellm.ai/"},{"label":"HOMEPAGE","url":"https://litellm.ai/"}],"relatedProjects":[{"id":"github.com/berriai/litellm","relationType":"SOURCE_REPO","relationProvenance":"UNVERIFIED_METADATA"}],"attestations":[],"verifiedAttestation":false,"projectStatus":"active"}},{"version":"1.73.6.post1","repositoryCount":1,"occurrenceCount":1,"ageDays":381,"advisoryIds":["GHSA-4xpc-pv4p-pm3w","GHSA-53mr-6c8q-9789","GHSA-69x8-hrgq-fjj8","GHSA-jjhc-v7c2-5hh6","GHSA-qrc4-49gv-mv9m","GHSA-wpfp-gwwc-vwq6"],"metadata":{"state":"resolved","checkedAt":"2026-07-20T03:19:50.101Z","publishedAt":"2025-07-04T00:34:40Z","deprecated":false,"deprecatedReason":null,"licenses":["MIT"],"advisoryIds":["GHSA-4xpc-pv4p-pm3w","GHSA-53mr-6c8q-9789","GHSA-69x8-hrgq-fjj8","GHSA-jjhc-v7c2-5hh6","GHSA-qrc4-49gv-mv9m","GHSA-wpfp-gwwc-vwq6","PYSEC-2026-2597","PYSEC-2026-2598","PYSEC-2026-2600","PYSEC-2026-388","PYSEC-2026-390"],"links":[{"label":"DOCUMENTATION","url":"https://docs.litellm.ai/"},{"label":"HOMEPAGE","url":"https://litellm.ai/"},{"label":"SOURCE_REPO","url":"https://github.com/BerriAI/litellm"}],"relatedProjects":[{"id":"github.com/berriai/litellm","relationType":"SOURCE_REPO","relationProvenance":"UNVERIFIED_METADATA"}],"attestations":[],"verifiedAttestation":false,"projectStatus":"active"}}]},"evidence":{"occurrences":[{"id":"component:87141138cb70fa11ff2eb1da","repositoryId":"opencode:5530","repositorySlug":"opencode-5530","repositoryName":"GSA Extraction","repositoryPathWithNamespace":"uba-ki-lab/gsa-extraction","ecosystem":"pypi","name":"litellm","identity":"pypi:litellm","version":"1.73.6.post1","versionKey":"pypi:litellm@1.73.6.post1","direct":null,"development":null,"sourceKind":"uv-lock","filePath":"uv.lock","blobSha":"fbb23733e647554b5678500b3f17f13bac7f77f5","sourceUrl":"https://gitlab.opencode.de/uba-ki-lab/gsa-extraction/-/blob/f5161e79d3f8c53877f9b1b0d72e1c10bff775ba/uv.lock","commitSha":"f5161e79d3f8c53877f9b1b0d72e1c10bff775ba"},{"id":"component:7de6abdb7189d478a342adb0","repositoryId":"opencode:7781","repositorySlug":"opencode-7781","repositoryName":"kiva-llm-gateway","repositoryPathWithNamespace":"baden-wuerttemberg/innenministerium/kiva.platform/kiva-llm-gateway","ecosystem":"pypi","name":"litellm","identity":"pypi:litellm","version":"1.67.4.dev1","versionKey":"pypi:litellm@1.67.4.dev1","direct":true,"development":false,"sourceKind":"exact-manifest-pin","filePath":"docker/build_from_pip/requirements.txt","blobSha":"71e038b62670a19b1c2d641b48f120ac3ef72546","sourceUrl":"https://gitlab.opencode.de/baden-wuerttemberg/innenministerium/kiva.platform/kiva-llm-gateway/-/blob/4a5cd798be9b97cc1bff7b30d930eafda774e380/docker/build_from_pip/requirements.txt","commitSha":"4a5cd798be9b97cc1bff7b30d930eafda774e380"},{"id":"component:5f9a3679ea2f28e35255bd9f","repositoryId":"opencode:5012","repositorySlug":"opencode-5012","repositoryName":"LLM Testframework","repositoryPathWithNamespace":"uba-ki-lab/llm-testframework","ecosystem":"pypi","name":"litellm","identity":"pypi:litellm","version":"1.68.0","versionKey":"pypi:litellm@1.68.0","direct":null,"development":null,"sourceKind":"uv-lock","filePath":"uv.lock","blobSha":"b4c29eab16a40db016821e4ea567956048a046ea","sourceUrl":"https://gitlab.opencode.de/uba-ki-lab/llm-testframework/-/blob/e8d6e99a1fa63b264e727acb553ed9b1499789b1/uv.lock","commitSha":"e8d6e99a1fa63b264e727acb553ed9b1499789b1"},{"id":"component:bf5c4eb342726fa48f5724db","repositoryId":"opencode:4112","repositorySlug":"opencode-4112","repositoryName":"Objection management","repositoryPathWithNamespace":"uba-ki-lab/objection-management","ecosystem":"pypi","name":"litellm","identity":"pypi:litellm","version":"1.53.7","versionKey":"pypi:litellm@1.53.7","direct":null,"development":null,"sourceKind":"uv-lock","filePath":"uv.lock","blobSha":"8515db65670904208e99397a2d7878af759c74f3","sourceUrl":"https://gitlab.opencode.de/uba-ki-lab/objection-management/-/blob/5c1425bf9990cf12c5ae8ada47d249710703af18/uv.lock","commitSha":"5c1425bf9990cf12c5ae8ada47d249710703af18"}],"occurrenceCount":4},"related":{"repositories":[{"id":"opencode:7781","slug":"opencode-7781","name":"kiva-llm-gateway","pathWithNamespace":"baden-wuerttemberg/innenministerium/kiva.platform/kiva-llm-gateway","versions":["1.67.4.dev1"],"evidenceCount":1},{"id":"opencode:5530","slug":"opencode-5530","name":"GSA Extraction","pathWithNamespace":"uba-ki-lab/gsa-extraction","versions":["1.73.6.post1"],"evidenceCount":1},{"id":"opencode:5012","slug":"opencode-5012","name":"LLM Testframework","pathWithNamespace":"uba-ki-lab/llm-testframework","versions":["1.68.0"],"evidenceCount":1},{"id":"opencode:4112","slug":"opencode-4112","name":"Objection management","pathWithNamespace":"uba-ki-lab/objection-management","versions":["1.53.7"],"evidenceCount":1}],"vulnerabilities":[{"id":"GHSA-4xpc-pv4p-pm3w","slug":"ghsa-4xpc-pv4p-pm3w-c72dbf83","dossier":false,"summary":"LiteLLM: Authentication Bypass via Host Header Injection","aliases":["CVE-2026-49468","PYSEC-2026-388"],"sourceIds":["GHSA-4xpc-pv4p-pm3w","PYSEC-2026-388"],"published":"2026-06-16T23:38:26Z","modified":"2026-07-18T17:30:30.617013067Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"}],"references":[{"type":"WEB","url":"https://github.com/BerriAI/litellm/security/advisories/GHSA-4xpc-pv4p-pm3w"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-49468"},{"type":"WEB","url":"https://access.redhat.com/security/cve/CVE-2026-49468"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2491520"},{"type":"PACKAGE","url":"https://github.com/BerriAI/litellm"},{"type":"WEB","url":"https://github.com/BerriAI/litellm/releases/tag/v1.84.0"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-4xpc-pv4p-pm3w"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/litellm/PYSEC-2026-388.yaml"},{"type":"PACKAGE","url":"https://pypi.org/project/litellm"},{"type":"WEB","url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-49468.json"}],"versionKeys":["pypi:litellm@1.53.7","pypi:litellm@1.67.4.dev1","pypi:litellm@1.68.0","pypi:litellm@1.73.6.post1"],"packageCount":1,"repositoryCount":4},{"id":"GHSA-53mr-6c8q-9789","slug":"ghsa-53mr-6c8q-9789-034179e7","dossier":false,"summary":"LiteLLM: Privilege escalation via unrestricted proxy configuration endpoint","aliases":["CVE-2026-35029","PYSEC-2026-2597"],"sourceIds":["GHSA-53mr-6c8q-9789","PYSEC-2026-2597"],"published":"2026-04-03T21:59:31Z","modified":"2026-07-13T16:43:01.087747831Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:N"}],"references":[{"type":"WEB","url":"https://github.com/BerriAI/litellm/security/advisories/GHSA-53mr-6c8q-9789"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-35029"},{"type":"PACKAGE","url":"https://github.com/BerriAI/litellm"},{"type":"PACKAGE","url":"https://pypi.org/project/litellm"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-53mr-6c8q-9789"}],"versionKeys":["pypi:litellm@1.53.7","pypi:litellm@1.67.4.dev1","pypi:litellm@1.68.0","pypi:litellm@1.73.6.post1"],"packageCount":1,"repositoryCount":4},{"id":"GHSA-69x8-hrgq-fjj8","slug":"ghsa-69x8-hrgq-fjj8-13befa28","dossier":false,"summary":"LiteLLM: Password hash exposure and pass-the-hash authentication bypass","aliases":[],"sourceIds":["GHSA-69x8-hrgq-fjj8"],"published":"2026-04-08T00:04:12Z","modified":"2026-04-17T01:29:14.845270912Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"}],"references":[{"type":"WEB","url":"https://github.com/BerriAI/litellm/security/advisories/GHSA-69x8-hrgq-fjj8"},{"type":"PACKAGE","url":"https://github.com/BerriAI/litellm"}],"versionKeys":["pypi:litellm@1.53.7","pypi:litellm@1.67.4.dev1","pypi:litellm@1.68.0","pypi:litellm@1.73.6.post1"],"packageCount":1,"repositoryCount":4},{"id":"GHSA-fh2c-86xm-pm2x","slug":"ghsa-fh2c-86xm-pm2x-ff1ac9ef","dossier":false,"summary":"LiteLLM Vulnerable to Denial of Service (DoS) via Crafted HTTP Request","aliases":["CVE-2024-8984","PYSEC-2026-1545"],"sourceIds":["GHSA-fh2c-86xm-pm2x","PYSEC-2026-1545"],"published":"2025-03-20T12:32:49Z","modified":"2026-07-07T17:56:56.562714379Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-8984"},{"type":"WEB","url":"https://github.com/BerriAI/litellm/commit/4f49f836aa844ac9b6bfbeff27e6f6b2b9cf3f61"},{"type":"PACKAGE","url":"https://github.com/BerriAI/litellm"},{"type":"WEB","url":"https://github.com/BerriAI/litellm/blob/8c5ff150f6142608ffe968e4e68429f978fda187/litellm/tests/test_spend_logs.py#L242"},{"type":"WEB","url":"https://huntr.com/bounties/554fc76b-3097-4223-b4cf-110b853e9355"},{"type":"PACKAGE","url":"https://pypi.org/project/litellm"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-fh2c-86xm-pm2x"}],"versionKeys":["pypi:litellm@1.53.7"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-fjcf-3j3r-78rp","slug":"ghsa-fjcf-3j3r-78rp-3506a50a","dossier":false,"summary":"LiteLLM Has an Improper Authorization Vulnerability","aliases":["CVE-2025-0628","PYSEC-2026-1546"],"sourceIds":["GHSA-fjcf-3j3r-78rp","PYSEC-2026-1546"],"published":"2025-03-20T12:32:52Z","modified":"2026-07-07T17:56:36.033233141Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-0628"},{"type":"WEB","url":"https://github.com/berriai/litellm/commit/566d9354aab4215091b2e51ad0333e948125fa1b"},{"type":"PACKAGE","url":"https://github.com/BerriAI/litellm"},{"type":"WEB","url":"https://huntr.com/bounties/6c0e2f75-2d03-42f9-9530-e16a973317fc"},{"type":"PACKAGE","url":"https://pypi.org/project/litellm"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-fjcf-3j3r-78rp"}],"versionKeys":["pypi:litellm@1.53.7"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-jjhc-v7c2-5hh6","slug":"ghsa-jjhc-v7c2-5hh6-5d2c89e6","dossier":false,"summary":"LiteLLM: Authentication bypass via OIDC userinfo cache key collision","aliases":["CVE-2026-35030","PYSEC-2026-390"],"sourceIds":["GHSA-jjhc-v7c2-5hh6","PYSEC-2026-390"],"published":"2026-04-03T21:59:50Z","modified":"2026-07-01T20:22:56.400828Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N"}],"references":[{"type":"WEB","url":"https://github.com/BerriAI/litellm/security/advisories/GHSA-jjhc-v7c2-5hh6"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-35030"},{"type":"PACKAGE","url":"https://github.com/BerriAI/litellm"},{"type":"PACKAGE","url":"https://pypi.org/project/litellm"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-jjhc-v7c2-5hh6"}],"versionKeys":["pypi:litellm@1.53.7","pypi:litellm@1.67.4.dev1","pypi:litellm@1.68.0","pypi:litellm@1.73.6.post1"],"packageCount":1,"repositoryCount":4},{"id":"GHSA-qrc4-49gv-mv9m","slug":"ghsa-qrc4-49gv-mv9m-c7358be2","dossier":false,"summary":"LiteLLM allows an authenticated internal_user to create API keys with access to routes that their role does not permit","aliases":["CVE-2026-47101","PYSEC-2026-2598"],"sourceIds":["GHSA-qrc4-49gv-mv9m","PYSEC-2026-2598"],"published":"2026-05-21T21:30:36Z","modified":"2026-07-13T16:42:56.741599701Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-47101"},{"type":"WEB","url":"https://github.com/BerriAI/litellm/commit/2220f3076ac89bd2a2e3439acf57dcfbec2434c9"},{"type":"WEB","url":"https://github.com/BerriAI/litellm/commit/5190bd07eb23a037745d86328096f54378f1614a"},{"type":"WEB","url":"https://github.com/BerriAI/litellm/commit/d910a95661fce3cdd36f3b06c03ecf9c46c6457c"},{"type":"WEB","url":"https://gist.github.com/13ph03nix/9ec616e1fdc77b3673509c60206e827f"},{"type":"PACKAGE","url":"https://github.com/BerriAI/litellm"},{"type":"WEB","url":"https://github.com/BerriAI/litellm/releases/tag/v1.83.14-stable"},{"type":"WEB","url":"https://huntr.com/bounties/8e75edfb-ff05-4e63-bfca-2d93d03fb3b9"},{"type":"WEB","url":"https://www.obsidiansecurity.com/blog/litellm-privilege-escalation-rce"},{"type":"WEB","url":"https://www.vulncheck.com/advisories/litellm-privilege-escalation-via-api-key-generation"},{"type":"PACKAGE","url":"https://pypi.org/project/litellm"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-qrc4-49gv-mv9m"}],"versionKeys":["pypi:litellm@1.53.7","pypi:litellm@1.67.4.dev1","pypi:litellm@1.68.0","pypi:litellm@1.73.6.post1"],"packageCount":1,"repositoryCount":4},{"id":"GHSA-wpfp-gwwc-vwq6","slug":"ghsa-wpfp-gwwc-vwq6-53d5ec36","dossier":false,"summary":"LiteLLM allows a user to modify their own user_role via the /user/update endpoint","aliases":["CVE-2026-47102","PYSEC-2026-2600"],"sourceIds":["GHSA-wpfp-gwwc-vwq6","PYSEC-2026-2600"],"published":"2026-05-21T21:30:37Z","modified":"2026-07-13T16:43:25.135559552Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-47102"},{"type":"WEB","url":"https://github.com/BerriAI/litellm/pull/25541"},{"type":"WEB","url":"https://github.com/BerriAI/litellm/commit/128d32d2494b759c5d15da3452452af4c6a34c01"},{"type":"WEB","url":"https://github.com/BerriAI/litellm/commit/e6f18ce75b111c9b93dc15c72894cbdeb53177ce"},{"type":"WEB","url":"https://gist.github.com/13ph03nix/9ec616e1fdc77b3673509c60206e827f"},{"type":"PACKAGE","url":"https://github.com/BerriAI/litellm"},{"type":"WEB","url":"https://github.com/BerriAI/litellm/releases/tag/v1.83.10-stable"},{"type":"WEB","url":"https://huntr.com/bounties/8e75edfb-ff05-4e63-bfca-2d93d03fb3b9"},{"type":"WEB","url":"https://www.obsidiansecurity.com/blog/litellm-privilege-escalation-rce"},{"type":"WEB","url":"https://www.vulncheck.com/advisories/litellm-privilege-escalation-via-user-update"},{"type":"PACKAGE","url":"https://pypi.org/project/litellm"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-wpfp-gwwc-vwq6"}],"versionKeys":["pypi:litellm@1.53.7","pypi:litellm@1.67.4.dev1","pypi:litellm@1.68.0","pypi:litellm@1.73.6.post1"],"packageCount":1,"repositoryCount":4}]}}
