LiteLLMGHSA-879v-fggm-vxw2
LiteLLM Has a Leakage of Langfuse API Keys
High7.5CVE-2025-0330 · Published Mar 20, 2025 · updated Sep 10, 2026
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| litellm PyPI | <= 1.52.1 | No fix yet |
Details and references
In berriai/litellm version v1.52.1, an issue in proxy_server.py causes the leakage of Langfuse API keys when an error occurs while parsing team settings. This vulnerability exposes sensitive information, including langfuse_secret and langfuse_public_key, which can provide full access to the Langfuse project storing all requests.
- CVSS 3.0
- CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-1230
- Also known as
- CVE-2025-0330, PYSEC-2026-1543
More LiteLLM advisories
All LiteLLM| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Mar 202025 | LiteLLM Vulnerable to Denial of Service (DoS) CVE-2024-10188High7.5fixed in 1.53.1.dev1 | High7.5 | 1.53.1.dev1 |
| Mar 202025 | LiteLLM Vulnerable to Remote Code Execution (RCE) CVE-2024-6825High8.8no fix yet | High8.8 | No fix yet |
| Mar 202025 | LiteLLM Vulnerable to Denial of Service (DoS) via Crafted HTTP Request CVE-2024-8984High7.5fixed in 1.56.2 | High7.5 | 1.56.2 |
| Mar 202025 | LiteLLM Reveals Portion of API Key via a Logging File CVE-2024-9606High7.5fixed in 1.44.12 | High7.5 | 1.44.12 |
| Mar 202025 | LiteLLM Has an Improper Authorization Vulnerability CVE-2025-0628High8.1fixed in 1.61.15 | High8.1 | 1.61.15 |
| Sep 132024 | LiteLLM Server-Side Request Forgery (SSRF) vulnerability CVE-2024-6587High7.5fixed in 1.44.8 | High7.5 | 1.44.8 |