LiteLLM Vulnerability Chain Lets Low-Privilege Users Take Over AI Gateway Servers
Medium Severity
Global
Date OccurredJun 15, 202616:39 UTC
Event TypeCyber Intelligence
SourceTheHackerNews
RecordedJun 15, 2026
Full Description
A default low-privilege account on a LiteLLM proxy can climb to full admin and run code on the server by chaining three vulnerabilities, researchers at Obsidian Security disclosed
LiteLLM is a widely