logo

LiteLLM Vulnerability Chain Lets Low-Privilege Users Take Over AI Gateway Servers

ID: 085b95e8-ca03-5709-a9cf-2379d9f48669

STIX ID: report--085b95e8-ca03-5709-a9cf-2379d9f48669

Feed Name: The Hacker News

Threat Score
90/100

Date Published: 2026-06-15

Date Updated: 2026-06-16

Author: [email protected] (The Hacker News)

...
...

Obsidian Security disclosed a three-CVE chain in LiteLLM that lets a low-privilege account bypass route checks, escalate to proxy_admin, and achieve remote code execution (RCE), exposing provider keys, decrypted credentials, database access, and all requests/responses routed through the proxy; upgrade to LiteLLM v1.83.14-stable or later and audit proxy_admin accounts, guardrails, callbacks, and stored secrets.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.