{"data":{"id":"42e6b799-25cd-4211-a4f8-3df0369ee650","title":"GHSA-879v-fggm-vxw2: LiteLLM Has a Leakage of Langfuse API Keys","summary":"In berriai/litellm version v1.52.1, an issue in proxy_server.py leaks Langfuse API keys when an error occurs while parsing team settings. The exposed langfuse_secret and langfuse_public_key can provide full access to the Langfuse project that stores all requests.","solution":"N/A -- no mitigation discussed in source.","labels":["security","privacy"],"sourceUrl":"https://github.com/advisories/GHSA-879v-fggm-vxw2","publishedAt":"2025-03-20T12:32:52.000Z","cveId":"CVE-2025-0330","cweIds":["CWE-1230"],"cvssScore":"7.5","cvssSeverity":"high","severity":"high","attackType":["pii_leakage"],"issueType":"vulnerability","affectedPackages":["litellm@<= 1.52.1"],"affectedPackageNames":["litellm"],"affectedPackageRefs":["pypi:litellm"],"affectedVendors":[],"affectedVendorsRaw":["LiteLLM","Langfuse"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","summaryPromptVersion":"v2","headline":null,"headlinePromptVersion":null,"cvssVector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","attackVector":"network","attackComplexity":"low","privilegesRequired":"none","userInteraction":"none","exploitMaturity":"unknown","epssScore":0.00555,"epssCheckedAt":"2026-10-10T04:57:10.937Z","kevDateAdded":null,"advisoryAliases":["GHSA-879v-fggm-vxw2"],"affectedPackagesSource":null,"affectedPackagesCheckedAt":null,"patchAvailable":null,"disclosureDate":"2025-03-20T12:32:52.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"trivial","impactType":["confidentiality"],"aiComponentTargeted":"api","llmSpecific":true,"classifierConfidence":0.93,"researchCategory":null,"atlasIds":null}}