CVE-2026-59821 Security Incident affecting AI
Evidence indicates that the affected technology is affected by a security issue. Reported affected versions include 0.1.0.
What Happened
Evidence indicates that the affected technology is affected by a security issue. Reported affected versions include 0.1.0.
Why This Matters
Current evidence identifies a security issue involving the affected technology, but does not yet support a more specific impact claim.
Recommended Action
Upgrade litellm to 1.82.0 or later. Identify deployments of the affected technology matching the evidenced affected versions: 0.1.0.
Exposure
Apr 03, 2026 05:30
Apr 03, 2026 05:30
Exploitation status: UNKNOWN
Affected versions: 0.1.0
Primary entities:
Authoritative Intelligence
Timeline
-
Incident first seen
Apr 03, 2026 05:30BugSkan first recorded this incident.
-
AI Firm Mercor Confirms Breach as Hackers Claim 4TB of Stolen Data - Hackread
Apr 03, 2026 05:30hackread.com · Data Leak
Sources
hackread.com · Apr 03, 2026 05:30
AI firm Mercor confirmed a breach stemming from a supply chain attack involving the open-source LiteLLM PyPI package, where attackers published malicious versions after compromising maintainer credentials. This incident led to the alleged theft of 4TB of sensitive data, including candidate profiles, PII, source code, and API keys, subsequently listed by the Lapsus$ extortion group.
Open publisher sourceWatchlist Match
Create an account to see which incidents overlap with the technologies you monitor.