Skip to content

project

LiteLLM

LiteLLM is an open-source gateway/proxy that routes calls to many LLM providers through one API, offering logging, spend tracking, and self-hosted deployment.

Known aliases

  • BerriAI LiteLLM
  • BerriAI/litellm
  • Berri LiteLLM
  • ghcr.io/berriai/litellm
  • litellm
  • LiteLLM-class gateways
  • LiteLLM gateway
  • LiteLLM proxy
  • LiteLLM Python v1
  • LiteLLM Rust beta

Relationships

No evidence-backed relationships are recorded.

Current stories

build1 publisher

LiteLLM's Lens moves agent-failure analysis into the self-hosted gateway that routes model calls

LiteLLM launched Lens on September 30, a tool that uses AI agents to find recurring failures across agent traces sent through its model gateway. Customers host the analyzer and its databases, and the 200,000-trace volume CTO Ishaan Jaffer cites is a future target Lens has not been measured against.

Publishers:runtimewire.com

Reality

Evidence40
Adoption
Insufficient
Hype gap+25
Incentives60
Confidence40
security4 publishers

Google traces most of 2026's exploitation growth to fast n-day weaponization

Google's threat intelligence group counts 18 exploited flaws a month in 2026, up from 10.5 in 2025, while zero-days rose only from eight to 11. GTIG attributes most of the added attacks to fast weaponization of disclosed n-days, so the exposure sits in the days after a patch ships.

Perspective Coverage

4 publishers
Builder
Builder 33%
Operator
Operator 61%
Investor
Investor 6%

Reality

Evidence72
Adoption
Insufficient
Hype gap+30
Incentives35
Confidence65
security17 publishers

AFP sizes the Shai-Hulud syndicate's take at more than 500,000 credentials

Two men arrested in Australia this week are alleged TeamPCP members. The AFP estimate filed alongside the case puts the worm's take at more than 500,000 credentials and 300GB of data, and that scale makes token lifetime the live question.

Perspective Coverage

17 publishers
Builder
Builder 33%
Operator
Operator 50%
Investor
Investor 17%

Reality

Evidence68
Adoption
Insufficient
Hype gap+25
Incentives55
Confidence62
security13 publishers

CISA's seven new KEV entries put SonicWall gateways and Artifactory on one patch clock

SonicWall's CVSS 10.0 SSRF chains into command execution on remote access appliances, and JFrog Artifactory hands unauthenticated attackers admin under default configuration. Reverse shells and miners are already landing.

Perspective Coverage

13 publishers
Builder
Builder 24%
Operator
Operator 63%
Investor
Investor 13%

Reality

Evidence72
Adoption30
Hype gap+15
Incentives55
Confidence68

Earlier coverage

  1. An OpenAI evaluation model broke out of its sandbox through a flaw it found in its own package proxy

    Security · September 17, 2026 · 1 publisher

  2. LiteLLM's MCP endpoint answered a failed key check with an empty auth object

    Build · September 16, 2026 · 1 publisher

  3. One slash in a Host header moves the path Starlette's middleware checks

    Build · September 16, 2026 · 1 publisher

  4. A $14.34 router matched Opus-5's score on LiteLLM's 21-task benchmark

    Invest · September 15, 2026 · 1 publisher

  5. Whoever implements the server half of Responses picks your retrieval and veto defaults

    Build · September 15, 2026 · 1 publisher

  6. Mohdel 1.0 computes per-call cost from a price catalog you maintain yourself

    Build · September 11, 2026 · 1 publisher

  7. Uber halved the cost of an AI session by routing work away from frontier models

    Leadership · September 11, 2026 · 1 publisher

  8. Uber's AI cost per session fell 18 points further than its cost per request

    Build · September 10, 2026 · 1 publisher

  9. MCP's shipped auth extension buys the agent's token with an employee's browser login

    Build · September 8, 2026 · 1 publisher

  10. Google traces a six-hour credential harvest to a coding chatbot running markdown playbooks

    Product · September 8, 2026 · 1 publisher

  11. A backdoored LiteLLM package cleared 119,000 downloads before PyPI quarantined it

    Build · September 5, 2026 · 1 publisher

  12. A query string smuggled into the Host header makes Starlette skip authentication

    Build · September 4, 2026 · 1 publisher

  13. Malicious litellm PyPI releases tied to Trivy scan dependency bypassed official CI/CD

    Security · September 3, 2026 · 1 publisher

  14. AFP charges two men near Perth over the self-spreading worm behind the TeamPCP compromises

    Security · August 28, 2026 · 1 publisher

  15. CISA's exploited-vulnerability catalog now reaches the LLM gateway

    Build · September 2, 2026 · 1 publisher

  16. A free Artifactory plugin can hold npm and PyPI versions until they age in public

    Security · September 2, 2026 · 1 publisher

  17. Move AI guardrails into the gateway before every service ships its own copy

    Build · September 2, 2026 · 1 publisher

  18. The compatibility probe wore the one User-Agent the CDN rule allowed

    Build · August 31, 2026 · 1 publisher

  19. Every one of thirteen named 2025-26 incidents ran on a credential that still worked

    Build · August 31, 2026 · 1 publisher

  20. Jackal IV's 58 arrests cover under a third of the suspects INTERPOL identified

    Security · August 28, 2026 · 1 publisher

  21. TeamPCP hid its infostealer inside the scanners that audit everyone else's code

    Science · August 28, 2026 · 1 publisher

  22. Exposed AI tooling now outnumbers exposed ICS hosts by more than two to one

    Security · August 28, 2026 · 1 publisher

  23. Someone enumerated LiteLLM's key tables 36 hours after the advisory hit defender feeds

    Security · August 28, 2026 · 1 publisher

  24. A backdoored litellm release turns every CI job that installed it into a credential incident

    Science · August 28, 2026 · 1 publisher

  25. Oligo dates the crew behind ShadowRay 2.0's self-propagating botnet back to 2020

    Security · August 28, 2026 · 1 publisher

  26. Experiential Labs bets its open-source router's traces will train cheaper replacements for rented models

    Build · August 27, 2026 · 1 publisher

  27. An exposed LiteLLM gateway hands over every key in PID 1's environment

    Build · August 27, 2026 · 1 publisher

  28. Attackers hid a cryptominer inside a LiteLLM MCP config test that reported success

    Security · August 27, 2026 · 1 publisher

  29. Microsoft's own incident data says the AI gateway is now the credential store

    Security · August 26, 2026 · 1 publisher

  30. The 97% saving was an agent failing quietly: token metrics need a completion gate

    Build · August 25, 2026 · 1 publisher

  31. 56 build-pipeline attacks, one vendor's alert queue, and the February jump nobody can attribute yet

    Build · August 23, 2026 · 1 publisher

  32. LiteLLM 1.82.7 and 1.82.8 shipped an infostealer: rotate everything those machines touched

    Science · August 20, 2026 · 1 publisher

  33. LiteLLM's 40 minutes on PyPI: 153GB of loot, 2,488 named orgs, and the victims nobody can name

    Science · August 19, 2026 · 1 publisher

  34. OX Security says MCP command execution is a design choice, so server owners own the risk

    Science · August 19, 2026 · 1 publisher

  35. Ornith-1.0's benchmarks are fine. Ollama can't parse its tool calls.

    Build · August 18, 2026 · 1 publisher

  36. VECT 2.0 shreds anything over 128 KB, which makes paying its ransom pointless

    Leadership · August 18, 2026 · 1 publisher

  37. A 12MB Go binary bets agent cost control is cache stickiness, not a dashboard

    Build · August 18, 2026 · 1 publisher

  38. Zalando's durable agentic engineering win was a proxy, not a model

    Build · August 17, 2026 · 1 publisher

  39. The agent stack's attack surface is trust: pin the deps, audit the MCP servers

    Build · August 16, 2026 · 1 publisher

  40. The 2,500-org compromise was a Trivy problem. LiteLLM was the closing act.

    Security · August 14, 2026 · 1 publisher