Executive brief
LiteLLM is a popular proxy server for managing API keys and LLM access control. A flaw in the key management system allows any internal user (a lower privilege level) to block or unblock any API key in the system, including those belonging to administrators. An attacker with basic internal access could disable critical production keys, causing service outages, or re-enable malicious keys without detection or audit trail.
Technical details
The vulnerability is an authorization bypass (CWE-266, CWE-285) in the key_management_endpoints.py file within the /key/block and /key/unblock endpoints. These endpoints are included in internal_user_routes, meaning they pass initial middleware authentication checks for any internal_user token holder. However, the endpoint implementations (block_key and unblock_key functions) lack secondary authorization checks to verify that the requestor owns the target key or holds proxy_admin privileges. As a result, the application only validates the caller has internal_user role via middleware and then freely modifies the database status of any provided key string. The attack requires network access to the LiteLLM proxy and a valid internal_user API token, but no additional privileges or user interaction. An attacker can perform both denial-of-service (blocking keys) and potential privilege abuse (unblocking malicious keys). The vulnerability is exploitable and publicly disclosed; no patched version is currently available in the advisory.
Affected products
- BerriAI litellm <= 1.63.1
Timeline
- 2026-03-21: disclosed: Vulnerability reported/disclosed
- 2026-06-21: advisory: Published to GitHub Advisory Database and NVD