๐Ÿ” CVE Alert

CVE-2026-12774

MEDIUM 6.3

BerriAI litellm MCP Server Connection Testing rest_endpoints.py _execute_with_mcp_client server-side request forgery

CVSS Score
6.3
EPSS Score
0.0%
EPSS Percentile
0th

A security vulnerability has been detected in BerriAI litellm up to 1.82.2. Affected by this vulnerability is the function _execute_with_mcp_client of the file litellm/proxy/_experimental/mcp_server/rest_endpoints.py of the component MCP Server Connection Testing. The manipulation leads to server-side request forgery. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure.

CWE CWE-918
Vendor berriai
Product litellm
Published Jun 21, 2026
Stay Ahead of the Next One

Get instant alerts for berriai litellm

Be the first to know when new medium vulnerabilities affecting berriai litellm are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

BerriAI / litellm
1.82.0 1.82.1 1.82.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
vuldb.com: https://vuldb.com/vuln/372516 vuldb.com: https://vuldb.com/vuln/372516/cti vuldb.com: https://vuldb.com/cve/CVE-2026-12774 vuldb.com: https://vuldb.com/submit/811285 gist.github.com: https://gist.github.com/YLChen-007/256c8ff0750e298f89b6b287c90c2981

Credits

๐Ÿ” Eric-c (VulDB User) VulDB CNA Team