Skip to content
HighVulnerabilityLLM-specific

GHSA-g5pg-73fc-hjwq: LiteLLM Reveals Portion of API Key via a Logging File

Published
Record updated
View JSON
Affected
  • litellm < 1.44.12
Fixed in
1.44.12
Known exploitation
Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
EPSS
0.8%

Summary

In berriai/litellm before version 1.44.12, the API key masking code in litellm/litellm_core_utils/litellm_logging.py masks only the first 5 characters of a key. As a result, almost the entire API key appears in the logs. The issue affects version v1.44.9.

Mitigation

The source does not state a fix yet. Check the original advisory for updates.