HighVulnerabilityLLM-specific
GHSA-g5pg-73fc-hjwq: LiteLLM Reveals Portion of API Key via a Logging File
- Identifiers
- CVE-2024-9606GHSA-g5pg-73fc-hjwq
- Published
- Record updated
- Affected
- litellm < 1.44.12
- Fixed in
- 1.44.12
- Known exploitation
- Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
- EPSS
- 0.8%
Summary
In berriai/litellm before version 1.44.12, the API key masking code in litellm/litellm_core_utils/litellm_logging.py masks only the first 5 characters of a key. As a result, almost the entire API key appears in the logs. The issue affects version v1.44.9.
Mitigation
The source does not state a fix yet. Check the original advisory for updates.
Affected packages in the Exposure Registry
Matched by package name and ecosystem. Each entry shows whether the package delegates to a language model and how many tracked packages depend on it.
- litellmPyPILLM dependency since 2023-07-27 · 54 tracked dependents
Related items
- LowGHSA-3gh4-cghq-f8v4: Pydantic AI OpenTelemetry instrumentation: retry prompt content is not redacted when `include_content=False`Similar attack · GitHub Advisory Database
- LowGHSA-4x9p-g9wm-8q7f: Pydantic AI OpenTelemetry instrumentation: exception events on tool and agent run spans include content when `include_content=False`Similar attack · GitHub Advisory Database
- LowSeptember 2026 Cyber Threat Landscape: Global Attacks Jump 48% as Phishing and GenAI Data Exposure RiseSimilar attack · Check Point Research
- InfoSystemic privacy risks of personal data exposure through conversational large language model agentsSimilar attack · OpenAlex (peer-reviewed AI security)
- InfoA novel privacy-preserving large language model integrating trust-weighted and ethical gradient maskingSimilar attack · OpenAlex (peer-reviewed AI security)