ended6월 12일· 1 sources
LiteLLM Authentication Bypass Opens AI Gateway to Unauthenticated RCE
AI 게이트웨이 LiteLLM 적극 악용 중, 인증 우회로 원격 코드 실행
Why it matters
LiteLLM sits at the heart of AI infrastructure, controlling traffic between applications and LLM providers while managing sensitive API keys and credentials. The vulnerability is being actively exploited and can chain with another CVE to bypass authentication entirely, giving attackers unauthenticated remote code execution. Organizations using LiteLLM must prioritize patching immediately, as CISA's inclusion in its Known Exploited Vulnerabilities catalog confirms real-world attacks are already underway.
1
Sources
+0
24h
—
Growth
5d
Active
LiteLLMCommand injectionAI gatewayRemote code executionCISA