IA Squad
SearchPT

semantic-router

python · semantic-routerCritical

semantic-router 0.1.8–0.1.14: Malicious litellm dependency exfiltrates credentials

semantic-router versions 0.1.8 through 0.1.14 declare `litellm>=1.61.3` with no upper bound, allowing a malicious `litellm==1.82.8

27 Jun 2026 · act now