GHSA-98x5-vq43-vc5pCritical▾ Midnightsemantic-router exposed to compromised litellm wheel (CVE-2026-42208) via unbounded transitive pin
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 52.3 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
semantic-router versions 0.1.8 through 0.1.14 declare litellm>=1.61.3 with no upper bound. During the window in which litellm==1.82.8 was the latest release on PyPI, a fresh install of any affected semantic-router version could resolve to that compromised wheel.
The malicious litellm==1.82.8 wheel ships a litellm_init.pth file that executes on Python interpreter startup — no import required. It collects and exfiltrates:
Stage-two payload encrypts the collected data (AES-256 + embedded RSA pubkey) and POSTs it to https://models.litellm.cloud/.
See upstream: BerriAI/litellm#24512 and CVE-2026-42208.
Fixed in semantic-router 0.1.15, which raises the floor to litellm>=1.83.7.
If developers cannot upgrade immediately:
litellm>=1.83.7,!=1.82.8 explicitly in their own project.site-packages/ for litellm_init.pth and delete if present.Upstream report and triage by the litellm maintainers — see issue #24512.
One caveat before publishing
CVE-2026-42208 specifically names 1.82.8. Pip's resolver picks "latest matching", so the real affected blast radius for semantic-router is users who ran pip install during the window that 1.82.8 was on PyPI — not everyone who ever installed 0.1.8–0.1.14. The advisory is still correct (an affected install could have pulled the bad wheel), but consider whether a Severity: Critical / Exploitability: time-bounded note would help downstream readers understand the exposure model.
semantic-router >= 0.1.8, < 0.1.15Upgrade to a patched release:
semantic-router 0.1.15Connected by shared product, vendor, weakness, or advisory.
GHSA-93qj-5q5v-3c2hCriticalTrojanized pantheon-agents 0.6.1 and 0.6.2 on PyPI ship a credential stealer (supply-chain account compromise)
CVE-2024-3094Critical· 10.0Malicious backdoor in xz/liblzma (supply-chain compromise)
CVE-2026-97230NoneIO::Socket::SSL::SelfCertificate versions 1.00 for Perl contains malware which executes Python code from an obfuscated URL. The generate_certificate runs a Python script saved as a certificate file
CVE-2026-74232Critical· 9.8Zbtlink L3_V2_8 firmware 3.0.0.4.528, Zbtlink WE826-T2 firmware 19.1101, Zbtlink ZBT-7628 firmware 1.0.0.2.007, Zbtlink ZBT-ZBT7621 firmware 1.0.0.3.001, MoreQuick MQAC-7620, MQAC-7620A, MQAP-7620, MQAP-7620A, and MQAP-7628 firmware 1.0.…
CVE-2026-67595High· 8.1VaahCMS 2.0.0 - 2.3.4 Malicious JavaScript Supply Chain via security-otp.blade.php
CVE-2025-30066High· 8.6tj-actions changed-files before 46 allows remote attackers to discover secrets by reading actions logs