CVE-2025-0628
CVSS 3.0 Score 8.1 of 10 (high)
Details
Published Mar 20, 2025
CWE ID 285
Summary
CVE-2025-0628 is an authorization vulnerability affecting the main-latest version of BerriAI/litellm. Users with the 'internal_user_viewer' role are granted overly privileged API keys upon login. These keys can be exploited to access all admin functionalities, including endpoints like '/users/list' and '/users/get_users'. Consequently, any account can escalate privileges and assume the role of a PROXY ADMIN. This issue poses a significant risk to the application's security, as it allows unauthorized access and manipulation of user data.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- BerriAI LiteLLM