GITHUBEXPLOIT 8.8 HIGH

Exploit for Incorrect Authorization in Litellm_1342A5F1-91D3-5C8E-BB29-7C09A496BF3B

8.8 / 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Description

CVE-2026-35029 — LiteLLM /config/update 越权访问漏洞 Broken Access Control LiteLLM 的 /config/update 端点未检查调用者的角色权限。任何持有有效 API Key 的已认证用户(无需管理员权限)均可修改代理配置,注册恶意 Pass-Through 端点以实现 环境变量窃取、任意文件读取、远程代码执行等攻击。 | Field | Value | |-------|-------| | CVE |...
Visit Original Source

Basic Information

ID 1342A5F1-91D3-5C8E-BB29-7C09A496BF3B
Published May 19, 2026 at 08:08
Modified May 19, 2026 at 08:09

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.