{"data":{"id":"766d9674-6fbc-4c6a-b295-350e77976afd","title":"GHSA-g5pg-73fc-hjwq: LiteLLM Reveals Portion of API Key via a Logging File","summary":"In berriai/litellm before version 1.44.12, the API key masking code in litellm/litellm_core_utils/litellm_logging.py masks only the first 5 characters of a key. As a result, almost the entire API key appears in the logs. The issue affects version v1.44.9.","solution":"N/A -- no mitigation discussed in source.","labels":["security"],"sourceUrl":"https://github.com/advisories/GHSA-g5pg-73fc-hjwq","publishedAt":"2025-03-20T12:32:51.000Z","cveId":"CVE-2024-9606","cweIds":["CWE-117"],"cvssScore":"7.5","cvssSeverity":"high","severity":"high","attackType":["pii_leakage"],"issueType":"vulnerability","affectedPackages":["litellm@< 1.44.12 (fixed: 1.44.12)"],"affectedPackageNames":["litellm"],"affectedPackageRefs":["pypi:litellm"],"affectedVendors":[],"affectedVendorsRaw":["LiteLLM"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","summaryPromptVersion":"v2","headline":null,"headlinePromptVersion":null,"cvssVector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","attackVector":"network","attackComplexity":"low","privilegesRequired":"none","userInteraction":"none","exploitMaturity":"unknown","epssScore":0.00752,"epssCheckedAt":"2026-10-10T04:57:10.639Z","kevDateAdded":null,"advisoryAliases":["GHSA-g5pg-73fc-hjwq"],"affectedPackagesSource":null,"affectedPackagesCheckedAt":null,"patchAvailable":true,"disclosureDate":"2025-03-20T12:32:51.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"trivial","impactType":["confidentiality"],"aiComponentTargeted":"api","llmSpecific":true,"classifierConfidence":0.95,"researchCategory":null,"atlasIds":null}}