vulnerability
LiteLLM Vulnerability Chain Lets Low-Privilege Users Take Over AI Gateway Servers
Critical
Summary
A critical vulnerability chain in LiteLLM, an open-source AI gateway, allows low-privilege users to escalate their permissions to full administrator and execute arbitrary code on the server. Researchers at Obsidian Security discovered this chain, which involves an authorization bypass, privilege escalation, and a sandbox escape, resulting in exposure of sensitive data like API keys and prompts. The vulnerability, rated CVSS 9.9, highlights the risks associated with open-source AI gateways and emphasizes the importance of timely updates.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
