{"id":"GHSA-98x5-vq43-vc5p","title":"semantic-router exposed to compromised litellm wheel (CVE-2026-42208) via unbounded transitive pin","summary":"semantic-router exposed to compromised litellm wheel (CVE-2026-42208) via unbounded transitive pin","severity":"critical","cwe":["CWE-506"],"vendor":"semantic-router","product":"semantic-router","ecosystem":"pip","affected":["semantic-router >= 0.1.8, < 0.1.15"],"patched":["semantic-router 0.1.15"],"published":"2026-06-26","updated":"2026-06-26","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-98x5-vq43-vc5p","references":[{"url":"https://github.com/aurelio-labs/semantic-router/security/advisories/GHSA-98x5-vq43-vc5p"},{"url":"https://github.com/advisories/GHSA-98x5-vq43-vc5p"}],"tags":["ghsa","pip"],"ingestedAt":"2026-06-29T13:24:35.265Z","slug":"GHSA-98x5-vq43-vc5p","body":"## Overview\n\n## Impact\nsemantic-router versions 0.1.8 through 0.1.14 declare `litellm>=1.61.3` with no upper bound. During the window in which `litellm==1.82.8` was the latest release on PyPI, a fresh install of any affected semantic-router version could resolve to that compromised wheel.\n\nThe malicious `litellm==1.82.8` wheel ships a `litellm_init.pth` file that executes on Python interpreter startup — no import required. It collects and exfiltrates:\n- Process environment variables\n- AWS / GCP / Azure credentials\n- SSH keys, Kubernetes configs, shell history\n- Database credentials and CI/CD secrets\n- Cryptocurrency wallets\n\nStage-two payload encrypts the collected data (AES-256 + embedded RSA pubkey) and POSTs it to `https://models.litellm.cloud/`.\n\nSee upstream: [BerriAI/litellm#24512](https://github.com/BerriAI/litellm/issues/24512) and [CVE-2026-42208](https://www.cve.org/CVERecord?id=CVE-2026-42208).\n\n## Patches\nFixed in **semantic-router 0.1.15**, which raises the floor to `litellm>=1.83.7`.\n\n## Workarounds\nIf developers cannot upgrade immediately:\n- Pin `litellm>=1.83.7,!=1.82.8` explicitly in their own project.\n- Audit `site-packages/` for `litellm_init.pth` and delete if present.\n- Rotate any credentials reachable from environments where an affected install ran.\n\n## Credit\nUpstream report and triage by the litellm maintainers — see issue [#24512](https://github.com/BerriAI/litellm/issues/24512).\n\nOne caveat before publishing\n\nCVE-2026-42208 specifically names 1.82.8. Pip's resolver picks \"latest matching\", so the real affected blast radius for semantic-router is users who ran pip install during the window that 1.82.8 was on PyPI — not everyone who ever installed 0.1.8–0.1.14. The advisory is still correct (an affected install could have pulled the bad wheel), but consider whether a Severity: Critical / Exploitability: time-bounded note would help downstream readers understand the exposure model.\n\n## Affected packages\n\n- `semantic-router >= 0.1.8, < 0.1.15`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `semantic-router 0.1.15`","depth":"midnight","depthScore":52,"depthScoreParts":{"impact":52.3,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}