important · AI infrastructure — LiteLLM
LiteLLM’s default management key can turn an exposed pre-1.82.0 proxy into effective unauthenticated root execution.
Affects
Self-hosted LiteLLM AI gateways, commonly deployed as containers in cloud environments to proxy model-provider traffic.
The documented sk-1234 key, or no master key, exposes administrative custom-code guardrails that run uploaded Python in the root proxy process and can expose cloud credentials.
Detail and 3 sources
A partial fix is published, but its complete effect was not assessed for this brief.
Sources
ResearchBreaking LiteLLM: From Auth Bypass to Cloud Compromise | Wiz BlogResearch公開LiteLLMの約1割が初期設定の管理鍵「sk-1234」を受け入れ — Wizが認証バイパスからクラウド侵害への連鎖を報告 | NEXSIGHT CYBER WIRECode / PoCfix Unauthenticated RCE and Sandbox Escape in Custom Code Guardrail by Harshit28j · Pull Request #22095 · BerriAI/litellm · GitHub