Skip to content
LiteLLMGHSA-879v-fggm-vxw2

LiteLLM Has a Leakage of Langfuse API Keys

High7.5CVE-2025-0330 · Published Mar 20, 2025 · updated Sep 10, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
litellm
PyPI
<= 1.52.1No fix yet
Details and references

In berriai/litellm version v1.52.1, an issue in proxy_server.py causes the leakage of Langfuse API keys when an error occurs while parsing team settings. This vulnerability exposes sensitive information, including langfuse_secret and langfuse_public_key, which can provide full access to the Langfuse project storing all requests.

CVSS 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-1230
Also known as
CVE-2025-0330, PYSEC-2026-1543

More LiteLLM advisories

All LiteLLM
DateAdvisory
Mar 202025LiteLLM Vulnerable to Denial of Service (DoS)
CVE-2024-10188High7.5fixed in 1.53.1.dev1
Mar 202025LiteLLM Vulnerable to Remote Code Execution (RCE)
CVE-2024-6825High8.8no fix yet
Mar 202025LiteLLM Vulnerable to Denial of Service (DoS) via Crafted HTTP Request
CVE-2024-8984High7.5fixed in 1.56.2
Mar 202025LiteLLM Reveals Portion of API Key via a Logging File
CVE-2024-9606High7.5fixed in 1.44.12
Mar 202025LiteLLM Has an Improper Authorization Vulnerability
CVE-2025-0628High8.1fixed in 1.61.15
Sep 132024LiteLLM Server-Side Request Forgery (SSRF) vulnerability
CVE-2024-6587High7.5fixed in 1.44.8

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.