Affected Technology

litellm incidents

LiteLLM proxy and SDK package

Matching incidents

5

Technology type

Package

Low severity RESOLVED

LiteLLM: Authenticated SSRF and provider-credential exfiltration via unvalidated request

### Impact Any authenticated LiteLLM proxy user could redirect an outbound provider call to a destination they control and cause the proxy to send its own configured provider credentials to that destination. The proxy's request-body validation was a denylist that did not cover every sensitive parameter and did not inspect parameters nested inside other request fields, so a caller could supply a routing or credential value that the proxy applied without clearing the operator's stored key. Any authenticated user could therefore exfiltrate the operator's upstream provider credentials and other configured secrets, and perform Server-Side Request Forgery against internal services reachable from the proxy. ### Patches Fixed in 1.96.2, 1.95.1, 1.94.3, 1.93.2, 1.92.2, 1.91.5, 1.90.7, 1.89.7, and 1.88.6. ### Workarounds Set `general_settings.allow_client_side_credentials` to `false` so callers cannot override connection parameters, restrict proxy keys to trusted callers, and block the affected parameters (`api_base`, `base_url`, `model_list`, `fallbacks`, provider credential fields) at a reverse proxy or API gateway.

litellmvulnerabilityAuthenticated SSRFBerriAI/litellmand
Low severity NEW

LiteLLM Security Incident

### Summary A server-side request forgery in LiteLLM Proxy lets an authenticated caller redirect the proxy's outbound request to a host of their choosing by smuggling an `api_base` inside the `user_config` request body, bypassing the existing parameter guard. ### Details LiteLLM Proxy validates request bodies with `is_request_body_safe`, which blocks the `api_base` and `base_url` parameters but does not cover `user_config`. The `user_config` object is used to build the outbound router for a request, so a caller can place an `api_base` inside it and reach an arbitrary host. The guard only inspected the two top-level keys, so the same `api_base` nested inside `user_config` was never checked. Exploitation requires a valid virtual key. ### Impact An authenticated caller can make the proxy issue server-side requests to internal or external hosts of their choosing, reaching endpoints the caller cannot otherwise access. ### Affected / Patched Affected: `

litellmvulnerabilityLiteLLM ProxyBerriAI/litellmreleased
Low severity STABLE

AI Supply-Chain Compromise

The Australian Federal Police (AFP) has charged two Western Australian men with a combined total of 14 offences over their alleged role in TeamPCP, the cybercrime group behind the March 2026 compromise of the open-source security scanners Trivy and Checkmarx KICS and the AI gateway LiteLLM. Louis Michael Gaebler, 23, and Ruben Ian Thomson, 21, appeared in Perth Magistrates Court on August 27,

Remote Code ExecutionSupply ChainChargedAlleged TeamPCP HackersAustralia Over MajorSupply Chain Attacks
1 source: thehackernews.com Updated 1mo ago

Back to intelligence feed