Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

Off Guard: Breaking LiteLLM from authentication bypass to cloud compromise

Summary

Wiz Research: ~10% of 3,000 public LiteLLM instances accept the default key sk-1234 or no auth; chaining CVE-2026-59822 (MCP bypass) and CVE-2026-59821 reaches root RCE and cloud credential theft.
Published
Collected

original ↗

Related coverage

back