
Three chained vulnerabilities in LiteLLM let a low-privilege user escalate to full admin and execute code on the server. Obsidian Security rated the chain CVSS 9.9. BerriAI fixed the CVEs in LiteLLM v1.83.14-stable, released May 2. Upgrading closes the authorization bypass, privilege escalation, and remote code execution flaws.
Tap to vote and see what everyone thinks.
Summary by ByteBrief
Ivanti urges Sentry patch for critical bugs