Threat · curated 8 Aug 2026

Search results for database — Latest News, Reports & Analysis

Coverage timeline

8 Aug 2026thehackernews.com

Single-source advisory — first reported, latest, and curated coincide.

Why it matters

LiteLLM brokers calls to more than 100 model providers behind one interface, so a full server takeover of an exposed proxy hands attackers all provider keys and every prompt and response traversing the gateway.

Researchers at Obsidian Security disclosed a chain of three vulnerabilities in LiteLLM, a widely deployed open-source AI gateway, that lets a default low-privilege account escalate to full admin and execute code on the server. A takeover exposes every model-provider key it holds, the secrets decrypting its stored credentials, and all prompts and responses passing through it; Obsidian rates the full chain CVSS 9.9. Maintainer BerriAI shipped the complete fix in LiteLLM v1.83.14-stable.