build1 publisher
One unauthenticated request to LiteLLM's admin endpoint dumps every provider key the proxy routes
CISA's exploited-vulnerability catalog now holds entries for LiteLLM, Kestra and Starlette, according to a dev.to writeup, and the quickstart docs for those tools still keep provider API keys in the process environment an attacker reads first.
Publishers:dev.to
Reality
- Evidence28
- Adoption
- Insufficient
- Hype gap+42
- Incentives32
- Confidence34