CVE-2026-84377: LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to versions 1.88.6 and 1.96.2, any authenticated LiteLLM proxy user could redirect an outbound provider c...

Added to the CISA Known Exploited Vulnerabilities catalog on 02 Sep 2026. Vendor: AI/ML. Product: LLM. CVSS score: 6.5.

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to versions 1.88.6 and 1.96.2, any authenticated LiteLLM proxy user could redirect an outbound provider call to a destination the user controls and cause the proxy to send its configured provider credentia...

Required action: Review and patch if applicable to your AI infrastructure.