Vulnerability DatabaseGHSA-5mg7-485q-xm76

GHSA-5mg7-485q-xm76
LiteLLM vulnerability analysis and mitigation

After an API Token exposure from an exploited trivy dependency, two new releases of litellm were uploaded to PyPI containing automatically activated malware, harvesting sensitive credentials and files, and exfiltrating to a remote API. Anyone who has installed and run the project should assume any credentials available to litellm environment may have been exposed, and revoke/rotate thema ccordingly.


SourceNVD

Related LiteLLM vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-37004CRITICAL9.8
  • Chainguard logoChainguard
  • cpe:2.3:a:litellm:litellm
NoYesAug 27, 2026
CVE-2026-30623CRITICAL9.8
  • LiteLLM logoLiteLLM
  • cpe:2.3:a:litellm:litellm
NoNoJul 15, 2026
CVE-2026-59822HIGH8.8
  • NixOS logoNixOS
  • cpe:2.3:a:litellm:litellm
YesYesJul 08, 2026
CVE-2026-84377MEDIUM6.5
  • Chainguard logoChainguard
  • cpe:2.3:a:litellm:litellm
NoYesSep 02, 2026
CVE-2026-59821LOW2.1
  • NixOS logoNixOS
  • airflow-2
NoYesJul 08, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management