AIIC AI Intelligence Centre

SOURCE-LINKED INTELLIGENCE

GHSA-879v-fggm-vxw2: LiteLLM Has a Leakage of Langfuse API Keys

OSV AI package advisories · observation · Mar 20, 2025 · UTC

In berriai/litellm version v1.52.1, an issue in proxy_server.py causes the leakage of Langfuse API keys when an error occurs while parsing team settings. This vulnerability exposes sensitive information, including langfuse_secret and langfuse_public_key, which can provide full access to the Langfuse project storing all requests.

Read original source ↗ Open in workspace

recordType
vulnerability
status
active
evidenceStatus
reported
region
Global

Evidence & attribution

First collected: 2026-09-20T23:41:51.992Z. This is not the publication date.