Affected Systems
LiteLLM open-source AI gateway. Specific affected versions not disclosed. Impacts organizations using LiteLLM to manage API keys and route requests to AI providers (OpenAI, Anthropic, etc.).
Exploitation Status
Vulnerability chain disclosed by Obsidian Security researchers. No CVE assigned yet. Public exploitation status unknown, but technical details likely available given researcher disclosure.
Business Impact
Critical risk for organizations using LiteLLM in production. Successful exploitation grants attackers full administrative control and remote code execution on the gateway server. All provider API keys (OpenAI, Anthropic, Azure OpenAI, etc.) and secrets stored in LiteLLM are exposed, enabling unauthorized AI service usage, data exfiltration, and potential supply chain attacks. Financial impact includes fraudulent API consumption charges and potential data breach costs.
Urgency
🔴 Immediate
Recommended Actions
- Identify all LiteLLM deployments in your environment and assess exposure (internet-facing vs. internal)
- Review LiteLLM user accounts and remove or demote any unnecessary low-privilege accounts until patched
- Monitor LiteLLM access logs for privilege escalation attempts or unexpected admin activity
- Rotate all AI provider API keys managed by LiteLLM instances as a precautionary measure
- Apply vendor patches immediately when released; subscribe to LiteLLM GitHub security advisories for updates
