SHABATH
SHABATH
GCC CYBERSECURITY
HomeServicesNews & Articles
Back to news
Article1 min read

LiteLLM Vulnerability Chain Lets Low-Privilege Users Take Over AI Gateway Servers

N
News
By · 2026-06-15
default low-privilege account on a LiteLLM proxy can climb to full admin and run code on the server by chaining three vulnerabilities, researchers at Obsidian Security disclosed LiteLLM is a widely deployed open-source AI gateway that brokers calls to more than 100 model providers behind one OpenAI-compatible interface. A server takeover exposes every provider key it holds, the secrets that decrypt its stored credentials, and every prompt and response passing through it. Obsidian rates the full chain CVSS 9.9, in the Critical range. BerriAI, the maintainer, included the complete fix set in LiteLLM v1.83.14-stable, which GitHub lists as released May 2. Upgrade to that release or later to close the three-CVE chain.
N
News
SHABATH · GCC Cybersecurity
Latest news & articles
Advisory1 min

73,932+ Fortinet firewalls compromised globally

This campaign exposes an automated operation targeting Fortinet firewalls and VPN gateways worldwide…

Article1 min

Hardening OT networks: a field guide

Practical steps for segmenting and monitoring operational technology.

Advisory1 min

Drone-borne RF interference near coastal terminals

Operators should review physical-cyber controls around exposed terminals.