litellm is vulnerable to Privilege Escalation
99
Critical Risk
LiteLLM's proxy encrypts both secrets stored in request metadata and UI/CLI session tokens with the same AES-GCM key and helper, with no domain separation between the two uses. An internal user can request a new virtual key with a metadata field holding a forged proxy_admin session payload as the "secret" value, then present the proxy's own encrypted response back as a bearer token. The proxy decrypts that token and accepts it as an admin session, so a low privileged user can escalate to proxy_admin and run arbitrary commands through the MCP stdio endpoint. The fix binds session token encryption to a distinct, prefix bound key context so a stored secret can no longer be replayed as a session token.
You are affected if you are using a version that falls within the vulnerable range.
litellm is vulnerable to Privilege Escalation in versions 1.91.0 - 1.100.3, 1.101.0 - 1.101.2, 1.102.0 - 1.102.1 and 1.103.0 - 1.103.0.
Upgrade the litellm library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.