Last updated: September 29, 2026 at 8:42 AM UTC
All 891 Vulnerability 357 Breach 144 Threat 383 Defense 7
Tag: ai-gateway (5 articles)Clear

Critical Bifrost AI gateway flaw lets unauthenticated attackers run commands and steal provider keys

JFrog disclosed a critical flaw in Bifrost, an open-source AI gateway routing to over twenty LLM providers, that lets an unauthenticated attacker run arbitrary commands on the gateway with a single HTTP request. Tracked as CVE-2026-90898 and rated 9.8, it affects all Bifrost HTTP transport versions before 2.1.0 when management authentication is disabled, which is the default. An attacker registers a stdio-type MCP client through an unauthenticated POST to /api/mcp/client, and Bifrost runs the command immediately, before any handshake, as the gateway user. Because the gateway stores API keys for every connected provider, command execution also exposes those credentials, and the official Docker image binds its management API to all interfaces.

Check
Upgrade Bifrost to transports 2.1.0, enable management authentication, keep the management listener off untrusted networks, and rotate any provider keys the gateway held.
Affected
Bifrost gateways before 2.1.0 with default disabled management auth let an unauthenticated attacker run commands and read every connected provider API key.
Fix
Update to 2.1.0, set governance.auth_config.is_enabled to true with strong credentials, avoid publishing the management port, and treat exposed instances as compromised.

Nearly one in ten exposed LiteLLM AI gateways still accept the example admin key

Researchers at Wiz found that nearly one in ten internet-facing LiteLLM servers still accept "sk-1234," the example administrator key printed in LiteLLM's own setup guide. LiteLLM is an open-source AI gateway that sits between an organization's apps and the model providers it pays for, and that admin key unlocks every stored provider API key; in Wiz's tests it even reached the cloud identity credentials of the host machine. The finding accompanies a cluster of exploited LiteLLM flaws that attackers have used to run code, steal secrets, and deploy crypto miners, with one ransomware group and a Microsoft-documented breach among them. Microsoft's advice is to treat AI gateways as top-tier secrets stores.

Check
Change the LiteLLM admin key immediately if it is still the default sk-1234, which needs no upgrade, and upgrade LiteLLM to 1.84.0 or later to close the exploited code-execution and auth-bypass flaws.
Affected
Organizations running internet-facing LiteLLM gateways, especially with the default admin key or on unpatched versions; an attacker can read every stored provider API key, reach cloud credentials, and sometimes execute code.
Fix
Replace default keys, patch to the latest LiteLLM, take gateways off the public internet, rotate all provider, cloud, and database credentials it can reach, and treat AI gateways as tier-zero secrets stores.

Attackers probe LiteLLM AI gateways to steal cloud and model provider secrets

Attackers are actively probing LiteLLM deployments for an authorization flaw that turns a low-privilege account into full control of the AI gateway. Tracked as CVE-2026-35029 and affecting versions before 1.83.0, the flaw is a missing permission check on the configuration-update endpoint, so a read-only user can change settings reserved for administrators. LiteLLM sits between applications and model providers and stores provider API keys, database details, and admin credentials, making it a rich target. By abusing configuration writes, an attacker can extract secrets from server environment files and even reset the dashboard login to seize admin access. Researchers recorded thousands of probing requests, some directly attempting to read known secret files.

Check
Upgrade LiteLLM to 1.83.0 or later, restrict access to its control plane and configuration endpoints, and rotate any provider, cloud, or database secrets the gateway could expose.
Affected
Organizations running LiteLLM before 1.83.0 as an AI gateway (CVE-2026-35029); a low-privilege authenticated user can modify configuration, read environment secrets, and escalate to administrator, exposing stored model provider and cloud credentials.
Fix
Patch, segment and firewall the LiteLLM control plane away from untrusted users, enforce least privilege, store secrets outside reachable environment files, rotate exposed keys, and monitor configuration endpoints for unauthorized changes.

LiteLLM AI gateway flaw exploited for unauthenticated remote code execution

Attackers are actively exploiting a flaw in LiteLLM, a widely used open-source gateway that routes requests to AI models, and CISA has added it to its known-exploited-vulnerabilities list. The bug (CVE-2026-42271) lets any authenticated user run commands on the host through test endpoints that spawn whatever command is supplied in the request. Chained with a separate Host-header bypass in the Starlette web framework (CVE-2026-48710), it becomes unauthenticated remote code execution, giving full control of the server, credential theft, and a foothold in connected AI infrastructure. Horizon3.ai has published a proof-of-concept. It follows a LiteLLM SQL injection flaw exploited within 36 hours last month.

Check
Identify internet-facing LiteLLM proxy deployments and their version, check the Starlette version in use, and review logs of the /mcp-rest/test endpoints for unexpected command execution.
Affected
LiteLLM AI gateway and Python SDK (BerriAI) deployments exposing the vulnerable test endpoints (CVE-2026-42271), especially when paired with Starlette versions vulnerable to the Host-header bypass (CVE-2026-48710).
Fix
Upgrade LiteLLM and Starlette to the fixed releases immediately, restrict the affected endpoints to trusted networks, and rotate any credentials or API keys reachable from the LiteLLM host.

Hackers raced to exploit a critical LiteLLM flaw 36 hours after disclosure - any attacker who could reach the proxy could read all stored AI API keys (CVE-2026-42208)

LiteLLM, the popular open-source gateway used to centralize API access for OpenAI, Anthropic, and other AI providers, has a critical pre-authentication SQL injection bug that attackers started exploiting just 36 hours after the security advisory went public. The flaw lets anyone who can reach the proxy port read all the API keys stored inside - including master keys, virtual keys, and provider credentials. The bug was in the bearer-token check: the token was concatenated into a SQL query instead of passed as a parameter. Sysdig saw the first attack at 04:24 UTC on April 26, hitting three tables that hold the most valuable secrets.

Check
If you run any internet-facing LiteLLM proxy, patch to v1.83.7-stable today and treat every API key, virtual key, and stored provider credential as compromised.
Affected
LiteLLM versions 1.81.16 through 1.83.6, internet-reachable on the default proxy port. CVE-2026-42208, CVSS 9.3, pre-auth SQL injection. Blast radius is closer to a full cloud account compromise than a typical web app bug because LiteLLM holds OpenAI, Anthropic, and AWS Bedrock credentials.
Fix
Patch to LiteLLM v1.83.7-stable. If you can't upgrade, set 'disable_error_logs: true' under 'general_settings' as a workaround. Rotate every virtual key, master key, and upstream provider credential. Audit upstream provider billing for unexpected API calls since April 24. Block traffic from 65.111.27.132 and 65.111.25.67 (AS200373).