Automate Society

Technology, IT and AI, sorted daily

Security

LiteLLM flaw turns internal users into proxy admins

A key used for two jobs lets users with the internal_user role gain admin rights and run commands on the host. Patched versions are out.

In the AI gateway LiteLLM, a signed-in user with the internal_user role can promote themselves to proxy_admin and then run arbitrary commands on the host. A security advisory the developers published on GitHub rates the flaw critical, with a CVSS score of 9.9. Versions from 1.91.0 onward are affected; the bug is fixed in 1.100.4, 1.101.3, 1.102.2, 1.103.1 and 1.104.0rc2. CERT-Bund at the BSI (Germany's federal cyber security agency) also lists the flaw and rates it "high"; no CVE number exists yet.

The root cause is a single key the proxy uses for two jobs: encrypting stored secrets and minting session tokens. An attacker requests an API key and puts forged admin details into its metadata field. They later present the encrypted response as a bearer token, and the proxy grants them admin rights, including command execution through the MCP stdio endpoint. Anyone who cannot upgrade right away can, according to the advisory, set EXPERIMENTAL_UI_LOGIN=false to switch off the vulnerable login path.

Why it matters: LiteLLM puts access to different language models behind one interface, which often makes it the central component in AI integrations. The attack needs nothing more than an ordinary user account; no admin access is required. Whoever takes over the proxy reaches the secrets stored there and the host itself. Anyone who gives teams or customers their own accounts on a LiteLLM instance should check the version first and then review the issued accounts and keys.

Discussion

I read every comment before it appears.

No comments yet. Yours would be the first.

Leave a comment

Never published, stored only as a checksum.