SOURCE-LINKED INTELLIGENCE
GHSA-g5pg-73fc-hjwq: LiteLLM Reveals Portion of API Key via a Logging File
In berriai/litellm before version 1.44.12, the `litellm/litellm_core_utils/litellm_logging.py` file contains a vulnerability where the API key masking code only masks the first 5 characters of the key. This results in the leakage of almost the entire API key in the logs, exposing a significant amount of the secret key. The issue affects version v1.44.9.
Read original source ↗ Open in workspace
- recordType
- vulnerability
- status
- active
- evidenceStatus
- reported
- region
- Global
Evidence & attribution
- OSV AI package advisories · 2025-03-20T12:32:51.000Z
- OSV AI package advisories · 2026-07-07T14:34:57.987Z
First collected: 2026-09-20T23:41:51.992Z. This is not the publication date.