目標達成 すべての支援者に感謝 — 100%達成しました!

目標: 1000 CNY · 調達済み: 1336 CNY

100%

berriai 厂商漏洞列表 / CVE 中文分析 38

berriai 厂商相关 38 条 CVE 漏洞,含 AI 中文分析、POC、CVSS 评分与受影响产品。

Berriai 是一家专注于人工智能安全工具开发的公司,其产品主要针对 AI 系统的安全漏洞检测与防护。历史上,其产品曾出现过多种安全漏洞,包括远程代码执行、跨站脚本请求伪造和权限绕过等问题。截至最新统计,该厂商相关产品已报告 18 条 CVE 记录,其中部分漏洞可导致攻击者完全控制系统。安全研究人员建议及时更新至最新版本,并实施严格的输入验证机制以降低风险。

上位製品 berriai: litellm berriai/litellm
CVE IDタイトルCVSS深刻度公開日
CVE-2026-59819 LiteLLM: Local file read via request-supplied OIDC file references — litellmCWE-73--2026-07-08
CVE-2026-59822 LiteLLM: MCP Authentication Bypass via OAuth2 Passthrough Fallback — litellmCWE-287--2026-07-08
CVE-2026-59820 LiteLLM: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') — litellmCWE-22--2026-07-08
CVE-2026-59821 LiteLLM: Custom Code Guardrails production endpoints bypass code safety checks — litellmCWE-94--2026-07-08
CVE-2026-49468 LiteLLM: Authentication Bypass via Host Header Injection — litellmCWE-290--2026-06-22
CVE-2026-12799 BerriAI litellm Incomplete Fix CVE-2025-0628 internal_user_endpoints.py ui_view_users improper authorization — litellmCWE-285 4.3 Medium2026-06-21
CVE-2026-12798 BerriAI litellm MCP OpenAPI Spec Loader openapi_to_mcp_generator.py load_openapi_spec_async server-side request forgery — litellmCWE-918 6.3 Medium2026-06-21
CVE-2026-12797 BerriAI litellm Completions banned_keywords.py async_pre_call_hook authorization — litellmCWE-863 6.3 Medium2026-06-21
CVE-2026-12796 BerriAI litellm SSO Authentication Flow ui_sso.py get_redirect_response_from_openid session expiration — litellmCWE-613 6.3 Medium2026-06-21
CVE-2026-12795 BerriAI litellm SSO Debug Flow ui_sso.py json.dumps missing authentication — litellmCWE-306 7.3 High2026-06-21
CVE-2026-12774 BerriAI litellm MCP Server Connection Testing rest_endpoints.py _execute_with_mcp_client server-side request forgery — litellmCWE-918 6.3 Medium2026-06-21
CVE-2026-12773 BerriAI litellm MCP Proxy user_api_key_auth_mcp.py UserAPIKeyAuth improper authentication — litellmCWE-287 7.3 High2026-06-21
CVE-2026-12772 BerriAI litellm PROXY_ADMIN database API Key Generator login_utils.py authenticate_user session expiration — litellmCWE-613 6.3 Medium2026-06-21
CVE-2026-12771 BerriAI litellm M2M JWT user_api_key_auth.py improper authorization — litellmCWE-285 5.0 Medium2026-06-21
CVE-2026-12770 BerriAI litellm Admin Key key_management_endpoints.py improper authorization — litellmCWE-285 5.4 Medium2026-06-21
CVE-2026-47102 LiteLLM < 1.83.10 Privilege Escalation via User Update — litellmCWE-863 8.8 High2026-05-21
CVE-2026-47101 LiteLLM < 1.83.14 Privilege Escalation via API Key Generation — litellmCWE-863 8.8 High2026-05-21
CVE-2026-42208 LiteLLM: SQL injection in Proxy API key verification — litellmCWE-89 9.1AICriticalAI2026-05-08
CVE-2026-42203 LiteLLM: Server-Side Template Injection in /prompts/test endpoint — litellmCWE-1336 9.6AICriticalAI2026-05-08
CVE-2026-42271 LiteLLM: Authenticated command execution via MCP stdio test endpoints — litellmCWE-77 9.8AICriticalAI2026-05-08
CVE-2026-40217 LiteLLM 安全漏洞 — LiteLLMCWE-420 8.8 High2026-04-10
CVE-2026-35030 LiteLLM has an authentication bypass via OIDC userinfo cache key collision — litellmCWE-287 6.5AIMediumAI2026-04-06
CVE-2026-35029 LiteLLM affected by privilege escalation via unrestricted proxy configuration endpoint — litellmCWE-863 8.8AIHighAI2026-04-06
CVE-2024-6825 Remote Code Execution in BerriAI/litellm — berriai/litellmCWE-94 9.8 -2025-03-20
CVE-2024-10188 Denial of Service in BerriAI/litellm — berriai/litellmCWE-400 7.5 -2025-03-20
CVE-2025-0628 Improper Authorization in BerriAI/litellm — berriai/litellmCWE-266 8.8 -2025-03-20
CVE-2025-0330 Exposure of Sensitive Information in berriai/litellm — berriai/litellmCWE-1230 7.5 -2025-03-20
CVE-2024-9606 Improper Output Neutralization for Logs in berriai/litellm — berriai/litellmCWE-117 7.5 -2025-03-20
CVE-2024-8984 Denial of Service (DoS) in berriai/litellm — berriai/litellmCWE-770 7.5 -2025-03-20
CVE-2024-6587 SSRF in berriai/litellm — berriai/litellmCWE-918 8.1AIHighAI2024-09-13

本页汇总了 berriai 厂商截至目前公开的全部 38 条 CVE 漏洞。每条漏洞均包含 CVSS 评分、CWE 弱点分类、受影响产品与参考链接,并附带 AI 生成的中文分析以便快速判断风险。