ended6월 16일· 1 sources
Three Critical Flaws Allow Complete LiteLLM Gateway Takeover from Default User
LiteLLM 기본 계정의 연쇄 취약점으로 AI Gateway 완전 장악 가능
Why it matters
A critical chain of three vulnerabilities in LiteLLM, widely-used open-source AI gateway handling over 100 model providers, enables attackers to escalate from default user privileges to full server compromise. This threatens to expose API keys for major services like OpenAI and Anthropic, along with all routed traffic and stored credentials. For organizations deploying LiteLLM as a central request broker, the threat is severe—the gateway's centralized position makes it an exceptionally high-value target when compromised.
1
Sources
+0
24h
—
Growth
97d
Active
LiteLLMvulnerability chainprivilege escalationauthorization bypasscode executionAPI gateway