Dev.to
6/15/2026

LiteLLM Vulnerability Chain Enables Full AI Gateway Takeover from Default Account
Short summary
LiteLLM AI gateway has three chained vulnerabilities (CVSS 9.9) allowing default users to bypass authorization, escalate to admin, and execute arbitrary code, exposing all API keys, credentials, and prompts. Attackers can silently manipulate AI responses via callbacks or MCP. Upgrade immediately to v1.83.14-stable.
- •Three chained CVEs (47101, 47102, 40217) enable default user → full server compromise via authorization bypass, privilege escalation, and code execution
- •Compromised proxy exposes all provider API keys, credentials, database secrets, and enables silent response manipulation in transit to AI agents
- •Affects any org running LiteLLM to broker AI model access; upgrade immediately to v1.83.14-stable or later
Generated with AI, which can make mistakes.
Is this a good recommendation for you?



