ended6월 12일· 1 sources

LiteLLM Authentication Bypass Opens AI Gateway to Unauthenticated RCE

AI 게이트웨이 LiteLLM 적극 악용 중, 인증 우회로 원격 코드 실행

Why it matters

LiteLLM sits at the heart of AI infrastructure, controlling traffic between applications and LLM providers while managing sensitive API keys and credentials. The vulnerability is being actively exploited and can chain with another CVE to bypass authentication entirely, giving attackers unauthenticated remote code execution. Organizations using LiteLLM must prioritize patching immediately, as CISA's inclusion in its Known Exploited Vulnerabilities catalog confirms real-world attacks are already underway.

1
Sources
+0
24h
Growth
5d
Active
LiteLLMCommand injectionAI gatewayRemote code executionCISA

Sources

Related Issues