Executive brief
LiteLLM is a tool used to manage and proxy requests to various AI models. A security flaw allows standard users to create new API keys that have administrative permissions they should not possess. This could allow a regular user to take full control of the proxy settings, access sensitive data, or disrupt AI services.
Technical details
An incorrect authorization vulnerability (CWE-863) exists in LiteLLM's key management endpoints. When an authenticated 'internal_user' generates a new API key, the 'allowed_routes' field is stored without verifying that the requested routes are within the scope of the creator's own permissions. Consequently, a low-privileged user can generate a key with access to administrative routes. By using this newly created key, the attacker can bypass role-based access controls (RBAC) and achieve full privilege escalation to 'proxy_admin'. The issue is fixed in version 1.83.14 by tightening caller-permission checks on key route fields.
Affected products
- BerriAI LiteLLM < 1.83.14
Timeline
- 2026-05-21: advisory: GitHub Advisory and NVD entry published
- 2026-05-21: patched: Version 1.83.14 released
References
- https://github.com/BerriAI/litellm/commit/2220f3076ac89bd2a2e3439acf57dcfbec2434c9
- https://github.com/BerriAI/litellm/commit/5190bd07eb23a037745d86328096f54378f1614a
- https://github.com/BerriAI/litellm/commit/d910a95661fce3cdd36f3b06c03ecf9c46c6457c
- https://gist.github.com/13ph03nix/9ec616e1fdc77b3673509c60206e827f
- https://github.com/BerriAI/litellm/releases/tag/v1.83.14-stable