Live data from GitHub and PyPI, updated daily.
Data last fetched: 2026-08-24
10 active CVEs reported via OSV.dev
Arbitrary file deletion in litellm
LiteLLM has Server-Side Template Injection vulnerability in /completions endpoint
LiteLLM: Local file read via request-supplied OIDC file references
LiteLLM: Authentication Bypass via Host Header Injection
LiteLLM Vulnerable to Remote Code Execution (RCE)
LiteLLM: Privilege escalation via unrestricted proxy configuration endpoint
LiteLLM: Arbitrary file write via path traversal in Skills archive extraction
Two LiteLLM versions published containing credential harvesting malware
LiteLLM: Password hash exposure and pass-the-hash authentication bypass
LiteLLM: Custom Code Guardrails production endpoints bypass code safety checks
Other AI / ML projects in the Python ecosystem worth evaluating.
Get SLA-backed support, security patches, and direct access to senior engineers for LiteLLM — without relying on volunteer maintainers.