Attackers are actively exploiting a critical authorization flaw in LiteLLM’s administrative API. This vulnerability allows low-privileged, read-only users to modify proxy configurations, expose sensitive secrets, and potentially gain full administrator control over affected servers. Researchers at Zenity Labs tracked approximately 3,900 requests targeting LiteLLM’s administration endpoints from February to June 2026, originating from 73 different […]
Read the original article: