logo

Hackers Can Turn Vulnerable LiteLLM AI Gateways Into Root Access and Cloud Credential Theft

ID: d261048a-f2c1-5bfa-97c4-cd8f9ae55a3a

STIX ID: report--d261048a-f2c1-5bfa-97c4-cd8f9ae55a3a

Feed Name: GBHackers

Threat Score
85/100

Date Published: 2026-09-10

Date Updated: 2026-09-11

Author: Mayura Kathir

...
...

Wiz researchers found widespread misconfigurations and multiple critical vulnerabilities in the open-source LiteLLM gateway that allow MCP authentication bypass, unprotected guardrail code execution leading to container root access, and administrative authorization flaws enabling proxying to cloud metadata services; CISA has added the MCP flaw to its Known Exploited Vulnerabilities catalog. Organizations are urged to upgrade to LiteLLM 1.84.0 (and 1.82.0-stable for guardrails), replace the default master key sk-1234, restrict MCP access, and audit guardrails and pass-through routes to prevent credential theft and lateral access.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.