LiteLLM Flaws Let Attackers Execute Code as Root and Steal Cloud Credentials
ID: 299dace2-ff1b-5600-904c-cd0e9c941da0
STIX ID: report--299dace2-ff1b-5600-904c-cd0e9c941da0
Feed Name: cybersecurityNews.com
**Executive summary:** Newly disclosed critical vulnerabilities in the LiteLLM AI gateway permit root remote code execution via insecure guardrail registration, an MCP authentication bypass that can establish sessions with a meaningless Bearer token, and configuration flaws that enable cloud metadata access and credential theft; researchers found many internet-facing instances accepting default keys and CISA added the issue to its Known Exploited Vulnerabilities list, so organizations should identify versions, patch to 1.82.0/1.84.0+, replace default credentials, audit pass-through settings, and rotate exposed cloud keys.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
