CVE-2026-12774: LiteLLM

Medium severity, CVSS 6.3. EPSS: 0.4% chance of exploitation in the next 30 days.

A security vulnerability has been detected in BerriAI litellm up to 1.82.2. Affected by this vulnerability is the function _execute_with_mcp_client of the file litellm/proxy/_experimental/mcp_server/rest_endpoints.py of the component MCP Server Connection Testing. The manipulation leads to server-side request forgery. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure.

Affected products

  • LiteLLM LiteLLM: up to and including 1.82.2

Published 2026-06-21. Last modified 2026-06-24.