negativeSYS.SOURCE: The Hacker News• 2026-09-10T12:42:55+05:30
Security Flaws in LiteLLM Gateways Expose Admin Credentials to 10% of Exposed Instances
Nearly 10% of exposed LiteLLM gateways accepted the default 'sk-1234' admin key, enabling unauthorized access to API keys and cloud credentials. Multiple vulnerabilities, including code execution and authentication bypass flaws, remain unpatched in some deployments.
Nearly one in ten of the internet-facing LiteLLM servers that Wiz Research scanned in February accepted sk-1234, the example admin key in LiteLLM's own setup guide.
LiteLLM is an open-source AI gateway, the software a company puts between its applications and the model providers it pays for. That key is the gateway's administrator credential.
Anyone who holds it can read every
*** END OF TRANSMISSION ***