CVE-2026-59821 Security Incident affecting AI
Evidence indicates that the affected technology is affected by a security issue. Reported affected versions include 0.1.0.
DEVELOPING
What Happened
Evidence indicates that the affected technology is affected by a security issue. Reported affected versions include 0.1.0.
Why This Matters
Current evidence identifies a security issue involving Mercor Hit, but does not yet support a more specific impact claim.
Recommended Action
Upgrade litellm to 1.82.0 or later. Identify deployments of Mercor Hit matching the evidenced affected versions: 0.1.0.
Exposure
Apr 01, 2026 05:30
Apr 02, 2026 05:30
Exploitation status: UNKNOWN
Affected versions: 0.1.0
Primary entities:
Authoritative Intelligence
Timeline
-
Incident first seen
Apr 01, 2026 05:30BugSkan first recorded this incident.
-
Mercor Hit by Supply Chain Attack via LiteLLM Breach - The Tech Buzz
Apr 01, 2026 05:30techbuzz.ai ยท Data Leak
-
Mercor Hit by LiteLLM Supply Chain Attack - SecurityWeek
Apr 02, 2026 05:30securityweek.com ยท Vulnerability
-
Latest observed development
Apr 02, 2026 05:30Most recent source or update associated with this incident.
-
Material change
Aug 18, 2026 14:07WATCH -> ACT
-
Material change
Aug 18, 2026 14:07recommended action updated
-
Material change
Aug 18, 2026 14:07why it matters updated
Sources
techbuzz.ai ยท Apr 01, 2026 05:30
An extortion group executed a supply chain attack by compromising the open-source LiteLLM project, which serves as a widely-used AI model API proxy. This breach led to the theft of sensitive data from AI recruiting startup Mercor, underscoring systemic vulnerabilities in the AI industry's reliance on unvetted open-source dependencies.
Open publisher sourcesecurityweek.com ยท Apr 02, 2026 05:30
Mercor was reportedly impacted by a supply chain attack involving the LiteLLM component, suggesting a potential compromise of software integrity or introduction of malicious dependencies. Due to the lack of article content, specific details regarding the exploit mechanism, a CVE, or the full impact are unavailable.
Open publisher sourceWatchlist Match
Create an account to see which incidents overlap with the technologies you monitor.