Back to feed
Dev.to
Dev.to
6/15/2026
LiteLLM Vulnerability Chain Enables Full AI Gateway Takeover from Default Account

LiteLLM Vulnerability Chain Enables Full AI Gateway Takeover from Default Account

Short summary

LiteLLM AI gateway has three chained vulnerabilities (CVSS 9.9) allowing default users to bypass authorization, escalate to admin, and execute arbitrary code, exposing all API keys, credentials, and prompts. Attackers can silently manipulate AI responses via callbacks or MCP. Upgrade immediately to v1.83.14-stable.

  • Three chained CVEs (47101, 47102, 40217) enable default user → full server compromise via authorization bypass, privilege escalation, and code execution
  • Compromised proxy exposes all provider API keys, credentials, database secrets, and enables silent response manipulation in transit to AI agents
  • Affects any org running LiteLLM to broker AI model access; upgrade immediately to v1.83.14-stable or later

Generated with AI, which can make mistakes.

Is this a good recommendation for you?

Comments

Failed to load comments. Please try again.

Explore more