CVE-2026-12774: LiteLLM
Medium severity, CVSS 6.3. EPSS: 0.4% chance of exploitation in the next 30 days.
A security vulnerability has been detected in BerriAI litellm up to 1.82.2. Affected by this vulnerability is the function _execute_with_mcp_client of the file litellm/proxy/_experimental/mcp_server/rest_endpoints.py of the component MCP Server Connection Testing. The manipulation leads to server-side request forgery. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure.
Affected products
- LiteLLM LiteLLM: up to and including 1.82.2
Published 2026-06-21. Last modified 2026-06-24.