Last seen April 2, 2026

CVE-2026-59821 Security Incident affecting AI

Evidence indicates that the affected technology is affected by a security issue. Reported affected versions include 0.1.0.

Technical Severity
Low severity
Lifecycle Status

DEVELOPING

What Happened

Evidence indicates that the affected technology is affected by a security issue. Reported affected versions include 0.1.0.

Why This Matters

Current evidence identifies a security issue involving Mercor Hit, but does not yet support a more specific impact claim.

Recommended Action

Upgrade litellm to 1.82.0 or later. Identify deployments of Mercor Hit matching the evidenced affected versions: 0.1.0.

Exposure

Recommended Response
First Seen

Apr 01, 2026 05:30

Last Seen

Apr 02, 2026 05:30

Exploitation status: UNKNOWN

Affected versions: 0.1.0

Primary entities:

Data Leakage Remote Code Execution Supply Chain CVE-2026-59821 CVE-2024-4888 CVE-2024-2952

Authoritative Intelligence

CVE CVE-2026-59821, CVE-2024-4888, CVE-2024-2952 +3 Incident identifier
NVD CVSS 2.1 LOW GitHub Advisory Database
Fixed Version 1.82.0, 1.35.36, 1.34.42 +2 Provider-backed
GHSA GHSA-72M8-9M7M-H278 GitHub advisory alias
CWE CWE-94 Weakness classification

Provider evidence: GitHub Advisory, OSV

EPSS is a vulnerability exploitation probability signal, not proof that your environment is exposed. CISA KEV means known exploitation of the vulnerability, not that your system was exploited.

Timeline

  • Incident first seen
    Apr 01, 2026 05:30

    BugSkan first recorded this incident.

  • Mercor Hit by Supply Chain Attack via LiteLLM Breach - The Tech Buzz
    Apr 01, 2026 05:30

    techbuzz.ai ยท Data Leak

  • Mercor Hit by LiteLLM Supply Chain Attack - SecurityWeek
    Apr 02, 2026 05:30

    securityweek.com ยท Vulnerability

  • Latest observed development
    Apr 02, 2026 05:30

    Most recent source or update associated with this incident.

  • Material change
    Aug 18, 2026 14:07

    WATCH -> ACT

  • Material change
    Aug 18, 2026 14:07

    recommended action updated

  • Material change
    Aug 18, 2026 14:07

    why it matters updated

Sources

Mercor Hit by Supply Chain Attack via LiteLLM Breach - The Tech Buzz

techbuzz.ai ยท Apr 01, 2026 05:30

An extortion group executed a supply chain attack by compromising the open-source LiteLLM project, which serves as a widely-used AI model API proxy. This breach led to the theft of sensitive data from AI recruiting startup Mercor, underscoring systemic vulnerabilities in the AI industry's reliance on unvetted open-source dependencies.

Open publisher source
Mercor Hit by LiteLLM Supply Chain Attack - SecurityWeek

securityweek.com ยท Apr 02, 2026 05:30

Mercor was reportedly impacted by a supply chain attack involving the LiteLLM component, suggesting a potential compromise of software integrity or introduction of malicious dependencies. Due to the lack of article content, specific details regarding the exploit mechanism, a CVE, or the full impact are unavailable.

Open publisher source

Watchlist Match

Want personalized relevance?

Create an account to see which incidents overlap with the technologies you monitor.

โ† Back to incident intelligence