Skip to content
HighVulnerabilityLLM-specific

GHSA-879v-fggm-vxw2: LiteLLM Has a Leakage of Langfuse API Keys

Published
Record updated
View JSON
Affected
  • litellm <= 1.52.1
Fixed in
No fixed version was stated when the source was last read.
Known exploitation
Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
EPSS
0.6%

Summary

In berriai/litellm version v1.52.1, an issue in proxy_server.py leaks Langfuse API keys when an error occurs while parsing team settings. The exposed langfuse_secret and langfuse_public_key can provide full access to the Langfuse project that stores all requests.

Mitigation

The source does not state a fix yet. Check the original advisory for updates.