ui_view_users of the file litellm/proxy/management_endpoints/internal_user_endpoints.py of the component Incomplete Fix CVE-2025-0628. Such manipulation leads to improper authorization.
This vulnerability is referenced as CVE-2026-12799. It is possible to launch the attack remotely. Furthermore, an exploit is available.
The vendor was contacted early about this disclosure.
Intelligence View
SOCIAL SHARE CARD GENERATOR