#litellm


Nearly 1 in 10 Exposed LiteLLM Gateways Accepted the Example “sk-1234” Admin Key

Sep 10, 2026 // 10:59

Nearly one in ten of the internet-facing LiteLLM servers that Wiz Research scanned in February accepted sk-1234, the example admin key in LiteLLM’s own setup […]

Malicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organizations

Aug 12, 2026 // 11:15

Two malicious LiteLLM releases sat on PyPI for about 40 minutes in March carrying credential-stealing code capable of harvesting cloud keys, SSH keys, Kubernetes tokens, […]

LiteLLM Vulnerability Chain Lets Low-Privilege Users Take Over AI Gateway Servers

Jun 15, 2026 // 22:49

A default low-privilege account on a LiteLLM proxy can climb to full admin and run code on the server by chaining three vulnerabilities, researchers at […]

LiteLLM Flaw CVE-2026-42271 Exploited in the Wild, Chains to Unauthenticated RCE

Jun 9, 2026 // 11:17

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a high-severity flaw impacting BerriAI LiteLLM to its Known Exploited Vulnerabilities (KEV) catalog, citing […]

LiteLLM CVE-2026-42208 SQL Injection Exploited within 36 Hours of Disclosure

May 1, 2026 // 00:42

In yet another instance of threat actors quickly jumping on the exploitation bandwagon, a newly disclosed critical security flaw in BerriAI’s LiteLLM Python package has […]

LiteLLM CVE-2026-42208 SQL Injection Exploited within 36 Hours of Disclosure

Apr 29, 2026 // 11:15

In yet another instance of threat actors quickly jumping on the exploitation bandwagon, a newly disclosed critical security flaw in BerriAI’s LiteLLM Python package has […]

Hackers are exploiting a critical LiteLLM pre-auth SQLi flaw

Apr 29, 2026 // 00:57

Hackers are targeting sensitive information stored in the LiteLLM open-source large-language model (LLM) gateway by exploiting a critical vulnerability  tracked as CVE-2026-42208. The flaw is […]

Compromised LiteLLM Package Stole Credentials, Tokens from PyPI Users

Mar 25, 2026 // 10:57

The hacking group TeamPCP is continuing its supply chain attacks, now targeting the widely used “LiteLLM” Python package on PyPI and claiming to have obtained […]

TeamPCP backdoors LiteLLM 1.82.7-1.82.8. Possible Trivy CI/CD compromise suspected.

Mar 24, 2026 // 22:33

The hacker group TeamPCP, responsible for past issues with Trivy and KICS, has now infiltrated the popular Python package litellm. They introduced two harmful versions […]

TeamPCP backdoors LiteLLM 1.82.7-1.82.8, likely via Trivy CI/CD breach.

Mar 24, 2026 // 22:24

The hacking group TeamPCP, known for recently breaching Trivy and KICS, has now infiltrated a widely used Python package called litellm. They introduced two infected […]