CVE-2026-108575 | BerriAI LiteLLM up to 1.94.0 Secret Resolution secret_managers/main.py get_secret api_key improper authorization

SecurityVulns

A vulnerability marked as critical has been reported in BerriAI LiteLLM up to 1.94.0. This affects the function get_secret of the file secret_managers/main.py of the component Secret Resolution. The manipulation of the argument api_key leads to improper authorization.

This vulnerability is documented as CVE-2026-108575. The attack can be initiated remotely. Additionally, an exploit exists.

The vendor was contacted early about this disclosure but did not respond in any way.VulDB Recent EntriesRead More