pypi:litellmThis dossier links the stable identity pypi:litellm to 4 exact observed versions across 4 public repositories.
A package identity or provider interface in published code does not prove configuration, an account, procurement, data transfer or an API call.
ecosystem:name + exact version + evidence pathPublication age and licenses come from deps.dev metadata. They are context—not a maintenance, legal or portability verdict.
05 Dec 202427 Apr 202504 May 202504 Jul 2025baden-wuerttemberg/innenministerium/kiva.platform/kiva-llm-gateway1 Occurrenceuba-ki-lab/gsa-extraction1 Occurrenceuba-ki-lab/llm-testframework1 Occurrenceuba-ki-lab/objection-management1 Occurrenceuba-ki-lab/gsa-extractionuv.lockbaden-wuerttemberg/innenministerium/kiva.platform/kiva-llm-gatewaydocker/build_from_pip/requirements.txtuba-ki-lab/llm-testframeworkuv.lockuba-ki-lab/objection-managementuv.lockLiteLLM: Local file read via request-supplied OIDC file references
10 Sept 2026LiteLLM: MCP Proxy Has Improper Authentication
11 Sept 2026LiteLLM: Authentication Bypass via Host Header Injection
10 Sept 2026LiteLLM: Privilege escalation via unrestricted proxy configuration endpoint
10 Sept 2026LiteLLM: Arbitrary file write via path traversal in Skills archive extraction
10 Sept 2026LiteLLM: Password hash exposure and pass-the-hash authentication bypass
10 Sept 2026LiteLLM: Admin Key Handler Has Improper Authorization
11 Sept 2026LiteLLM vulnerable to server-side template injection in the /prompts/test endpoint
10 Sept 2026LiteLLM: Custom Code Guardrails production endpoints bypass code safety checks
10 Sept 2026LiteLLM: MCP Authentication Bypass via OAuth2 Passthrough Fallback
10 Sept 2026BerriAI litellm has SSRF via Unvalidated spec_path URL in MCP OpenAPI Spec Loader
14 Sept 2026LiteLLM Vulnerable to Denial of Service (DoS) via Crafted HTTP Request
10 Sept 2026LiteLLM Has an Improper Authorization Vulnerability
10 Sept 2026LiteLLM Proxy has server-side request forgery via the `user_config` request parameter
17 Sept 2026LiteLLM: SSO Debug Flow Has Improper Authentication
11 Sept 2026LiteLLM: Authentication bypass via OIDC userinfo cache key collision
10 Sept 2026BerriAI litellm: UI User Enumeration leads to System-Wide Information Disclosure
14 Sept 2026LiteLLM: PROXY_ADMIN database API Key Generator Has Insufficient Session Expiration
10 Sept 2026BerriAI litellm has Security Feature Bypass in BannedKeywords and AzureContentSafety Guardrails via call_type Mismatch on Async Endpoints
14 Sept 2026LiteLLM: M2M JWT Handler Has Improper Authorization
10 Sept 2026LiteLLM allows an authenticated internal_user to create API keys with access to routes that their role does not permit
10 Sept 2026BerriAI litellm: SSO Login Does Not Invalidate Previous UI Session Tokens
14 Sept 2026LiteLLM allows a user to modify their own user_role via the /user/update endpoint
10 Sept 2026Only exact npm and PyPI tuples are enriched. Reported SPDX expressions are metadata; no compatibility, obligation or legal conclusion is inferred.
Retrieval, parsing, matching and publishing use no generative AI model.i6eal (2026): LiteLLM — exact AI dependency evidence dossier, data state 30 Sept 2026. https://i6eal.de/en/tools/ki-abhaengigkeitsatlas/paket/litellm-e00b5c8b/
We build source-backed data products with stable identities, reproducible joins and boundaries that remain visible.
These tools cover related ground.