Last seen April 3, 2026

CVE-2026-59821 Security Incident affecting AI

Evidence indicates that the affected technology is affected by a security issue. Reported affected versions include 0.1.0.

Technical Severity
Low severity
Lifecycle Status

STABLE

What Happened

Evidence indicates that the affected technology is affected by a security issue. Reported affected versions include 0.1.0.

Why This Matters

Current evidence identifies a security issue involving the affected technology, but does not yet support a more specific impact claim.

Recommended Action

Upgrade litellm to 1.82.0 or later. Identify deployments of the affected technology matching the evidenced affected versions: 0.1.0.

Exposure

Recommended Response
First Seen

Apr 03, 2026 05:30

Last Seen

Apr 03, 2026 05:30

Exploitation status: UNKNOWN

Affected versions: 0.1.0

Primary entities:

Credential Exposure Data Leakage Remote Code Execution Supply Chain CVE-2026-59821 CVE-2024-4888

Authoritative Intelligence

CVE CVE-2026-59821, CVE-2024-4888, CVE-2024-2952 +3 Incident identifier
NVD CVSS 2.1 LOW GitHub Advisory Database
Fixed Version 1.82.0, 1.35.36, 1.34.42 +2 Provider-backed
GHSA GHSA-72M8-9M7M-H278 GitHub advisory alias
CWE CWE-94 Weakness classification

Provider evidence: GitHub Advisory, OSV

EPSS is a vulnerability exploitation probability signal, not proof that your environment is exposed. CISA KEV means known exploitation of the vulnerability, not that your system was exploited.

Timeline

  • Incident first seen
    Apr 03, 2026 05:30

    BugSkan first recorded this incident.

  • AI Firm Mercor Confirms Breach as Hackers Claim 4TB of Stolen Data - Hackread
    Apr 03, 2026 05:30

    hackread.com · Data Leak

Sources

AI Firm Mercor Confirms Breach as Hackers Claim 4TB of Stolen Data - Hackread

hackread.com · Apr 03, 2026 05:30

AI firm Mercor confirmed a breach stemming from a supply chain attack involving the open-source LiteLLM PyPI package, where attackers published malicious versions after compromising maintainer credentials. This incident led to the alleged theft of 4TB of sensitive data, including candidate profiles, PII, source code, and API keys, subsequently listed by the Lapsus$ extortion group.

Open publisher source

Watchlist Match

Want personalized relevance?

Create an account to see which incidents overlap with the technologies you monitor.

← Back to incident intelligence