CyberRota Analysis
AI-GeneratedBerriAI LiteLLM versions prior to 1.101.0-rc.1 are vulnerable to a tenant isolation bypass in the semantic cache layer, allowing authenticated users to access cached responses from other tenants. This vulnerability can lead to exposure of sensitive information, including personally identifiable information and financial data, and may enable attackers to execute unauthorized actions under victim credentials. Organizations using affected versions should prioritize patching to mitigate the risk of data breaches and unauthorized access.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
BerriAI LiteLLM before 1.101.0-rc.1 contains a tenant isolation bypass vulnerability in the semantic cache layer that allows authenticated users to read other tenants' cached responses by exploiting a metadata key mismatch between _get_semantic_cache_tenant_scope() and _get_metadata_variable_name(). Attackers holding a valid virtual key can submit semantically similar prompts on affected routes such as /v1/responses and /bedrock/* to retrieve cached responses containing other tenants' personally identifiable information, financial data, or source code, and can cause agentic front-ends to auto-execute attacker-supplied tool calls under victim credentials by returning cached function_call or tool_calls payloads to a different principal.