HighVulnerabilityLLM-specific
GHSA-879v-fggm-vxw2: LiteLLM Has a Leakage of Langfuse API Keys
- Identifiers
- CVE-2025-0330GHSA-879v-fggm-vxw2
- Published
- Record updated
- Affected
- litellm <= 1.52.1
- Fixed in
- No fixed version was stated when the source was last read.
- Known exploitation
- Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
- EPSS
- 0.6%
Summary
In berriai/litellm version v1.52.1, an issue in proxy_server.py leaks Langfuse API keys when an error occurs while parsing team settings. The exposed langfuse_secret and langfuse_public_key can provide full access to the Langfuse project that stores all requests.
Mitigation
The source does not state a fix yet. Check the original advisory for updates.
Affected packages in the Exposure Registry
Matched by package name and ecosystem. Each entry shows whether the package delegates to a language model and how many tracked packages depend on it.
- litellmPyPILLM dependency since 2023-07-27 · 54 tracked dependents
Related items
- LowGHSA-3gh4-cghq-f8v4: Pydantic AI OpenTelemetry instrumentation: retry prompt content is not redacted when `include_content=False`Similar attack · GitHub Advisory Database
- LowGHSA-4x9p-g9wm-8q7f: Pydantic AI OpenTelemetry instrumentation: exception events on tool and agent run spans include content when `include_content=False`Similar attack · GitHub Advisory Database
- LowSeptember 2026 Cyber Threat Landscape: Global Attacks Jump 48% as Phishing and GenAI Data Exposure RiseSimilar attack · Check Point Research
- InfoSystemic privacy risks of personal data exposure through conversational large language model agentsSimilar attack · OpenAlex (peer-reviewed AI security)
- InfoA novel privacy-preserving large language model integrating trust-weighted and ethical gradient maskingSimilar attack · OpenAlex (peer-reviewed AI security)