Intel

AIKIDO-2025-10086

litellm is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor

Exposure of Sensitive Information to an Unauthorized Actor Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.

30

Low Risk

This Affects:

PYTHONlitellm
1.48.17 - 1.60.7
Fixed in 1.60.8

TL;DR

Affected versions of this library may leak Redis password on /cache/ping url.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

litellm is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor in versions 1.48.17 - 1.60.7.

How to fix this

Upgrade the litellm library to the patch version.