Overview
Researchers at Wiz.io have disclosed multiple vulnerabilities in LiteLLM, an open‑source AI gateway, that could allow attackers to execute code as root, bypass authentication, and steal cloud credentials. These flaws highlight the risks of insecure AI infrastructure, especially when deployed with weak configurations or exposed to the internet.
Key Vulnerabilities
- CVE‑2026‑59821:
- A flaw in LiteLLM’s Custom Code Guardrails feature allowed arbitrary code execution at the root level inside containers.
- Exploitation required administrative access, but weak deployments (default master key or no authentication) made this path trivial.
- Fixed in LiteLLM v1.82.0 with enforced admin roles and sandbox protections.
- CVE‑2026‑59822:
- An MCP authentication bypass allowed attackers to establish sessions with meaningless Bearer tokens.
- This opened access to connected tools like databases, repositories, and file systems.
- Fixed in LiteLLM v1.84.0.
- CVE‑2026‑35029:
- A flaw in the pass‑through configuration route lacked admin checks before v1.83.0.
- Attackers could forward requests to internal addresses, including AWS metadata services, to steal temporary IAM credentials.
Exposure Landscape
- Wiz.io scanned 3,074 internet‑facing LiteLLM instances.
- 294 (9.6%) accepted a default master key or had no authentication enabled.
- CISA added CVE‑2026‑59822 to its Known Exploited Vulnerabilities (KEV) catalog on September 2, 2026, confirming exploitation in the wild.
Risks to Cloud Infrastructure
LiteLLM often holds provider API keys and communicates with internal systems. If compromised, attackers can:
- Steal cloud credentials (e.g., AWS IAM keys).
- Invoke models and misuse costly resources.
- Harvest secrets and configuration data.
- Establish persistence across connected environments.
Defensive Guidance
Administrators should:
- Update LiteLLM to v1.84.0 or later.
- Replace default credentials with strong, unique master keys.
- Audit guardrails for malicious code.
- Restrict outbound traffic and enforce least‑privilege IAM permissions.
- Remove public exposure and limit access to trusted networks.
- Rotate provider keys if compromise is suspected.
- Review logs for unusual administrative actions or outbound requests.
Expert in the Cloud Insight
LiteLLM’s flaws demonstrate how AI gateways can become high‑value attack surfaces. When misconfigured, they expose root access, authentication bypasses, and cloud credential theft paths. The lesson is clear: AI infrastructure must be treated with the same rigor as privileged cloud services—patched quickly, hardened against exposure, and monitored for anomalies.
Leave a Reply