CVE-2026-59821 Security Incident affecting AI
Evidence indicates that the affected technology is affected by a security issue. Reported affected versions include 0.1.0.
DEVELOPING
What Happened
Evidence indicates that the affected technology is affected by a security issue. Reported affected versions include 0.1.0.
Why This Matters
Current evidence identifies a security issue involving the affected technology, but does not yet support a more specific impact claim.
Recommended Action
Upgrade litellm to 1.82.0 or later. Identify deployments of the affected technology matching the evidenced affected versions: 0.1.0.
Exposure
Apr 01, 2026 05:30
Apr 01, 2026 05:30
Exploitation status: UNKNOWN
Affected versions: 0.1.0
Primary entities:
Authoritative Intelligence
Timeline
-
Incident first seen
Apr 01, 2026 05:30BugSkan first recorded this incident.
-
AI startup Mercor confirms security incident linked to LiteLLM supply chain attack | brief | SC Media - SC Media
Apr 01, 2026 05:30scworld.com ยท Vulnerability
-
Mercor says it was hit by cyberattack tied to compromise of open source LiteLLM project - TechCrunch
Apr 01, 2026 05:30techcrunch.com ยท Data Leak
-
Material change
Aug 18, 2026 14:07WATCH -> ACT
-
Material change
Aug 18, 2026 14:07recommended action updated
-
Material change
Aug 18, 2026 14:07why it matters updated
-
Material change
Aug 18, 2026 14:07severity 8.5 -> 10.0
Sources
scworld.com ยท Apr 01, 2026 05:30
The incident stems from a supply chain attack targeting the open-source LiteLLM project, where malicious code was injected. This compromise led to thousands of organizations, including AI startup Mercor, suffering data breaches and exfiltration of sensitive information.
Open publisher sourcetechcrunch.com ยท Apr 01, 2026 05:30
Mercor, an AI recruiting startup, experienced a data breach following a supply chain attack on the open-source LiteLLM project, which involved the injection of malicious code into its packages. The Lapsus$ hacking group claimed responsibility for targeting Mercor and exfiltrating sensitive data, including Slack and ticketing information, as evidenced by shared samples.
Open publisher sourceWatchlist Match
Create an account to see which incidents overlap with the technologies you monitor.