Cybersecurity Alert: Vulnerabilities in LiteLLM Gateway Software Expose Sensitive Data
In a recent assessment by Wiz Research, a significant security issue has been identified in the LiteLLM gateway software, which facilitates connections between applications and AI model providers. The analysis revealed that nearly 10% of the LiteLLM servers publicly accessible on the internet were accepting a default administrator key, recognized as “sk-1234.” This key, which is disclosed within LiteLLM’s setup documentation, allows unauthorized users access to critical functionalities, notably the ability to read every model provider’s API key stored on the server and, in certain cases, access to the cloud Identity and Access Management (IAM) credentials of the hosting machine.
LiteLLM, which is an open-source AI gateway, is a critical component for businesses utilizing AI applications. When misconfigured, as seen in this instance, it poses a severe risk to organizational security. The master key not only serves as an admin credential but also functions as the switch that facilitates authentication for requests made through the gateway. Prior to version 1.82.0, any gateway initiated without a master key unwittingly granted full administrative privileges to all incoming requests, compounding the risk.
Wiz conducted its investigation in February, identifying a total of 3,074 LiteLLM gateways using Shodan, with 294 of these allowing the insecure default key. Alarmingly, 191 of these instances failed to set any key at all, meaning they would have accepted any incoming request. Following a subsequent scan, Wiz’s researchers noted an increase to over 85,000 instances by August, though it is believed many of these constitute honeypots or testing environments and should not be directly compared.
As of September 9, the original setup guide for LiteLLM still included the insecure key “sk-1234,” alongside a reminder instructing users to replace it with a long, random value before proceeding to a production environment. The persisting presence of this key underscores a critical lapse in securing the gateway software.
After examining the implications of a single administrative key, it becomes clear that the risks are serious. An administrator equipped with the default key could potentially view sensitive data, including API keys for all connected providers, along with prompts and responses navigated through the gateway using the Model Context Protocol (MCP). They could additionally wield privileges associated with the cloud instance housing the LiteLLM software, leading to the unauthorized execution of model workloads at the expense of the legitimate user—a practice referred to as LLMjacking.
Wiz’s findings indicate that while LiteLLM provides functionalities meant for trusted administrators, the inherent vulnerabilities could be exploited using MITRE ATT&CK techniques such as initial access and privilege escalation. The actions observed correlate with tactics where an adversary leverages insider access or misconfigurations to traverse the client environment and harvest credentials.
Despite the acknowledgment of these vulnerabilities, LiteLLM’s security policies have yet to label the failure to adequately secure the master key as a critical issue, placing it outside the scope of actively addressed vulnerabilities. Thus far, reported security issues have been categorized quietly without urgent patches, leaving critical entry points exposed to potential exploitation.
In summary, business owners utilizing LiteLLM should immediately assess their configurations. Upgrading to version 1.84.0 or later is essential to mitigate risks associated with the identified vulnerabilities. Additionally, administrators are strongly encouraged to change the default master key and review the access limitations of the gateway to prevent further unauthorized access. As organizations integrate AI solutions into their operations, vigilance in securing such gateways will be paramount in safeguarding against the accompanying cybersecurity threats.