Last seen April 1, 2026

CVE-2026-59821 Security Incident affecting AI

Evidence indicates that the affected technology is affected by a security issue. Reported affected versions include 0.1.0.

Technical Severity
Low severity
Lifecycle Status

DEVELOPING

What Happened

Evidence indicates that the affected technology is affected by a security issue. Reported affected versions include 0.1.0.

Why This Matters

Current evidence identifies a security issue involving the affected technology, but does not yet support a more specific impact claim.

Recommended Action

Upgrade litellm to 1.82.0 or later. Identify deployments of the affected technology matching the evidenced affected versions: 0.1.0.

Exposure

Recommended Response
First Seen

Apr 01, 2026 05:30

Last Seen

Apr 01, 2026 05:30

Exploitation status: UNKNOWN

Affected versions: 0.1.0

Primary entities:

Data Leakage Remote Code Execution Supply Chain CVE-2026-59821 CVE-2024-4888 CVE-2024-2952

Authoritative Intelligence

CVE CVE-2026-59821, CVE-2024-4888, CVE-2024-2952 +3 Incident identifier
NVD CVSS 2.1 LOW GitHub Advisory Database
Fixed Version 1.82.0, 1.35.36, 1.34.42 +2 Provider-backed
GHSA GHSA-72M8-9M7M-H278 GitHub advisory alias
CWE CWE-94 Weakness classification

Provider evidence: GitHub Advisory, OSV

EPSS is a vulnerability exploitation probability signal, not proof that your environment is exposed. CISA KEV means known exploitation of the vulnerability, not that your system was exploited.

Timeline

  • Incident first seen
    Apr 01, 2026 05:30

    BugSkan first recorded this incident.

  • AI startup Mercor confirms security incident linked to LiteLLM supply chain attack | brief | SC Media - SC Media
    Apr 01, 2026 05:30

    scworld.com ยท Vulnerability

  • Mercor says it was hit by cyberattack tied to compromise of open source LiteLLM project - TechCrunch
    Apr 01, 2026 05:30

    techcrunch.com ยท Data Leak

  • Material change
    Aug 18, 2026 14:07

    WATCH -> ACT

  • Material change
    Aug 18, 2026 14:07

    recommended action updated

  • Material change
    Aug 18, 2026 14:07

    why it matters updated

  • Material change
    Aug 18, 2026 14:07

    severity 8.5 -> 10.0

Sources

AI startup Mercor confirms security incident linked to LiteLLM supply chain attack | brief | SC Media - SC Media

scworld.com ยท Apr 01, 2026 05:30

The incident stems from a supply chain attack targeting the open-source LiteLLM project, where malicious code was injected. This compromise led to thousands of organizations, including AI startup Mercor, suffering data breaches and exfiltration of sensitive information.

Open publisher source
Mercor says it was hit by cyberattack tied to compromise of open source LiteLLM project - TechCrunch

techcrunch.com ยท Apr 01, 2026 05:30

Mercor, an AI recruiting startup, experienced a data breach following a supply chain attack on the open-source LiteLLM project, which involved the injection of malicious code into its packages. The Lapsus$ hacking group claimed responsibility for targeting Mercor and exfiltrating sensitive data, including Slack and ticketing information, as evidenced by shared samples.

Open publisher source

Watchlist Match

Want personalized relevance?

Create an account to see which incidents overlap with the technologies you monitor.

โ† Back to incident intelligence