litellm is vulnerable to Information Disclosure
41
Medium Risk
Affected versions of this package expose the full plaintext virtual key in error responses when an expired key is used, constituting a secrecy violation even though the key is no longer valid. An attacker can exploit this by capturing expired keys from logs, API responses, or monitoring systems and later abusing them if an administrator reactivates the key via the update endpoint, or by leveraging the leaked secret for audit evasion, access pattern reconstruction, or targeted social-engineering attacks, all of which violate standard secret-handling and compliance requirements.
You are affected if you are using a version that falls within the vulnerable range.
litellm is vulnerable to Information Disclosure in versions 0.1.0 - 1.80.14.
Upgrade the litellm library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant