← Back to the AI Dependency AtlasExact package identity dossier

LiteLLM

pypi:litellm
pypi

This dossier links the stable identity pypi:litellm to 4 exact observed versions across 4 public repositories.

pypipypi:litellmecosystem:name + exact version + evidence path

A package identity or provider interface in published code does not prove configuration, an account, procurement, data transfer or an API call.

ecosystem:name + exact version + evidence path
4repositories
4exact evidence rows
4exact versions
1reported license expression
23OSV records returned
Exact published evidence

Observed exact versions and registry metadata

Publication age and licenses come from deps.dev metadata. They are context—not a maintenance, legal or portability verdict.

Exact version1.53.705 Dec 2024
Repositories
1
Occurrences
1
Reported licenses
MIT
no verified publish attestation reported23 OSV records
Open exact source ↗
Exact version1.67.4.dev127 Apr 2025
Repositories
1
Occurrences
1
Reported licenses
MIT
no verified publish attestation reported20 OSV records
Open exact source ↗
Exact version1.68.004 May 2025
Repositories
1
Occurrences
1
Reported licenses
MIT
no verified publish attestation reported20 OSV records
Open exact source ↗
Exact version1.73.6.post104 Jul 2025
Repositories
1
Occurrences
1
Reported licenses
MIT
no verified publish attestation reported20 OSV records
Open exact source ↗
Observed relations

Repositories carrying this identity

kiva-llm-gatewaybaden-wuerttemberg/innenministerium/kiva.platform/kiva-llm-gateway
1.67.4.dev11 Occurrence
→
GSA Extractionuba-ki-lab/gsa-extraction
1.73.6.post11 Occurrence
→
LLM Testframeworkuba-ki-lab/llm-testframework
1.68.01 Occurrence
→
Objection managementuba-ki-lab/objection-management
1.53.71 Occurrence
→
Exact published evidence

exact evidence rows

GSA Extractionuba-ki-lab/gsa-extraction
pypi:litellm@1.73.6.post1uv.lock
declaration relationship not reporteddevelopment scope not reported
Open exact source ↗
kiva-llm-gatewaybaden-wuerttemberg/innenministerium/kiva.platform/kiva-llm-gateway
pypi:litellm@1.67.4.dev1docker/build_from_pip/requirements.txt
direct declarationnot marked as development-only
Open exact source ↗
LLM Testframeworkuba-ki-lab/llm-testframework
pypi:litellm@1.68.0uv.lock
declaration relationship not reporteddevelopment scope not reported
Open exact source ↗
Objection managementuba-ki-lab/objection-management
pypi:litellm@1.53.7uv.lock
declaration relationship not reporteddevelopment scope not reported
Open exact source ↗
OSV

Related OSV records

GHSA-4g5m-c9r5-49xf

LiteLLM: Local file read via request-supplied OIDC file references

4 repositories10 Sept 2026
GHSA-4jcj-7x88-m979

LiteLLM: MCP Proxy Has Improper Authentication

4 repositories11 Sept 2026
GHSA-4xpc-pv4p-pm3w

LiteLLM: Authentication Bypass via Host Header Injection

4 repositories10 Sept 2026
GHSA-53mr-6c8q-9789

LiteLLM: Privilege escalation via unrestricted proxy configuration endpoint

4 repositories10 Sept 2026
GHSA-5jmr-gcrj-2c9q

LiteLLM: Arbitrary file write via path traversal in Skills archive extraction

4 repositories10 Sept 2026
GHSA-69x8-hrgq-fjj8

LiteLLM: Password hash exposure and pass-the-hash authentication bypass

4 repositories10 Sept 2026
GHSA-6qr3-3g89-m4jj

LiteLLM: Admin Key Handler Has Improper Authorization

1 repository11 Sept 2026
GHSA-6wvf-77m9-58rm

LiteLLM vulnerable to server-side template injection in the /prompts/test endpoint

4 repositories10 Sept 2026
GHSA-72m8-9m7m-h278

LiteLLM: Custom Code Guardrails production endpoints bypass code safety checks

4 repositories10 Sept 2026
GHSA-7488-6r32-c95q

LiteLLM: MCP Authentication Bypass via OAuth2 Passthrough Fallback

4 repositories10 Sept 2026
GHSA-c693-x898-5g4h

BerriAI litellm has SSRF via Unvalidated spec_path URL in MCP OpenAPI Spec Loader

4 repositories14 Sept 2026
GHSA-fh2c-86xm-pm2x

LiteLLM Vulnerable to Denial of Service (DoS) via Crafted HTTP Request

1 repository10 Sept 2026
GHSA-fjcf-3j3r-78rp

LiteLLM Has an Improper Authorization Vulnerability

1 repository10 Sept 2026
GHSA-hx8v-g79f-8w5f

LiteLLM Proxy has server-side request forgery via the `user_config` request parameter

4 repositories17 Sept 2026
GHSA-j37q-q7p9-vpwm

LiteLLM: SSO Debug Flow Has Improper Authentication

4 repositories11 Sept 2026
GHSA-jjhc-v7c2-5hh6

LiteLLM: Authentication bypass via OIDC userinfo cache key collision

4 repositories10 Sept 2026
GHSA-m2v5-74w2-qhcj

BerriAI litellm: UI User Enumeration leads to System-Wide Information Disclosure

4 repositories14 Sept 2026
GHSA-mf52-j94g-746m

LiteLLM: PROXY_ADMIN database API Key Generator Has Insufficient Session Expiration

4 repositories10 Sept 2026
GHSA-p897-vf7j-f5h8

BerriAI litellm has Security Feature Bypass in BannedKeywords and AzureContentSafety Guardrails via call_type Mismatch on Async Endpoints

4 repositories14 Sept 2026
GHSA-qmf3-4767-5fg3

LiteLLM: M2M JWT Handler Has Improper Authorization

4 repositories10 Sept 2026
GHSA-qrc4-49gv-mv9m

LiteLLM allows an authenticated internal_user to create API keys with access to routes that their role does not permit

4 repositories10 Sept 2026
GHSA-w2mh-qq9q-453x

BerriAI litellm: SSO Login Does Not Invalidate Previous UI Session Tokens

4 repositories14 Sept 2026
GHSA-wpfp-gwwc-vwq6

LiteLLM allows a user to modify their own user_role via the /user/update endpoint

4 repositories10 Sept 2026
Interpretation boundary

Exact identities in, explicit limits out

Only exact npm and PyPI tuples are enriched. Reported SPDX expressions are metadata; no compatibility, obligation or legal conclusion is inferred.

Retrieval, parsing, matching and publishing use no generative AI model.

i6eal (2026): LiteLLM — exact AI dependency evidence dossier, data state 30 Sept 2026. https://i6eal.de/en/tools/ki-abhaengigkeitsatlas/paket/litellm-e00b5c8b/

Reading this dossier

Does package presence prove that a provider is used?
No. Even a direct interface declaration does not establish configuration, credentials, procurement, data transfer or an API call.
Why are exact versions required?
OSV and registry metadata can be linked reproducibly only to an observed package@version tuple. The collector never substitutes a newest release for a range.
Does a missing row mean the dependency is absent?
No. It means not observed within the bounded files and repository checkpoint. Incomplete trees and parser failures remain explicit.

Need a permanent dependency evidence trail for another public code cohort?

We build source-backed data products with stable identities, reproducible joins and boundaries that remain visible.

Discuss a data projectExplore all tools