Threat · curated 8 Aug 2026
Search results for database — Latest News, Reports & Analysis
First reported thehackernews.com
Coverage timeline
Single-source advisory — first reported, latest, and curated coincide.
Why it matters
LiteLLM brokers calls to more than 100 model providers behind one interface, so a full server takeover of an exposed proxy hands attackers all provider keys and every prompt and response traversing the gateway.
Researchers at Obsidian Security disclosed a chain of three vulnerabilities in LiteLLM, a widely deployed open-source AI gateway, that lets a default low-privilege account escalate to full admin and execute code on the server. A takeover exposes every model-provider key it holds, the secrets decrypting its stored credentials, and all prompts and responses passing through it; Obsidian rates the full chain CVSS 9.9. Maintainer BerriAI shipped the complete fix in LiteLLM v1.83.14-stable.