LiteLLM Under Fire: Triple Threat Vulnerabilities Expose AI Gateways to Total Takeover
ID: 5189ff8f-5da1-5eb7-a980-ec6d2723a0ea
STIX ID: report--5189ff8f-5da1-5eb7-a980-ec6d2723a0ea
Feed Name: securityonline.info
Researchers disclosed multiple critical vulnerabilities in the LiteLLM open-source library — most notably a CVSS 9.4 JWT/OIDC cache key collision allowing unauthenticated token spoofing, a pass-the-hash flaw due to unsalted SHA-256 password storage that leaks hashes via API endpoints, and a config update privilege bypass enabling RCE (CVE-2026-35029). Maintainers released v1.83.0 to hash JWT cache keys, migrate passwords to scrypt with salts and remove hashes from API responses, and restrict /config/update to proxy_admin; organizations are urged to upgrade or apply mitigations immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
