berriai/litellm version 1.34.34 is vulnerable to improper access control in its team management functionality. This vulnerability allows attackers to perform unauthorized actions such as creating, updating, viewing, deleting, blocking, and unblocking any teams, as well as adding or deleting any member to or from any teams. The vulnerability stems from insufficient access control checks in various team management endpoints, enabling attackers to exploit these functionalities without proper authorization.
                
            References
                    | Link | Resource | 
|---|---|
| https://huntr.com/bounties/70897f59-a966-4d93-b71e-745e3da91970 | Exploit Third Party Advisory | 
| https://huntr.com/bounties/70897f59-a966-4d93-b71e-745e3da91970 | Exploit Third Party Advisory | 
Configurations
                    History
                    15 Oct 2025, 13:15
| Type | Values Removed | Values Added | 
|---|---|---|
| CWE | CWE-862 | |
| CVSS | 
        v2 :  v3 :  | 
    
        v2 : unknown
         v3 : 6.5  | 
21 Nov 2024, 09:48
| Type | Values Removed | Values Added | 
|---|---|---|
| CVSS | 
        v2 :  v3 :  | 
    
        v2 : unknown
         v3 : 5.3  | 
| References | () https://huntr.com/bounties/70897f59-a966-4d93-b71e-745e3da91970 - Exploit, Third Party Advisory | 
20 Sep 2024, 18:04
| Type | Values Removed | Values Added | 
|---|---|---|
| CVSS | 
        v2 :  v3 :  | 
    
        v2 : unknown
         v3 : 6.5  | 
| CPE | cpe:2.3:a:litellm:litellm:1.34.34:*:*:*:*:*:*:* | |
| First Time | 
        
        Litellm
         Litellm litellm  | 
|
| CWE | NVD-CWE-noinfo | |
| References | () https://huntr.com/bounties/70897f59-a966-4d93-b71e-745e3da91970 - Exploit, Third Party Advisory | 
01 Jul 2024, 10:15
| Type | Values Removed | Values Added | 
|---|---|---|
| Summary | 
        
        
  | 
27 Jun 2024, 19:15
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2024-06-27 19:15
Updated : 2025-10-15 13:15
NVD link : CVE-2024-5710
Mitre link : CVE-2024-5710
CVE.ORG link : CVE-2024-5710
JSON object : View
Products Affected
                litellm
- litellm
 
CWE
                