news.mlab.sh
Back to the feed
vulnerability

LiteLLM Vulnerability Chain Lets Low-Privilege Users Take Over AI Gateway Servers

Critical
Image: The Hacker News
Summary

A critical vulnerability chain in LiteLLM, an open-source AI gateway, allows low-privilege users to escalate their permissions to full administrator and execute arbitrary code on the server. Researchers at Obsidian Security discovered this chain, which involves an authorization bypass, privilege escalation, and a sandbox escape, resulting in exposure of sensitive data like API keys and prompts. The vulnerability, rated CVSS 9.9, highlights the risks associated with open-source AI gateways and emphasizes the importance of timely updates.

Read the full article at The Hacker News

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.