LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.0, when JWT authentication is enabled (enable_jwt_auth: true), the OIDC userinfo cache uses token[:20] as the cache key. JWT headers produced by the same signing algorithm generate identical first 20 characters. This configuration option is not enabled by default. Most instances are not affected. An unauthenticated attacker can craft a token whose first 20 characters match a legitimate user's cached token. On cache hit, the attacker inherits the legitimate user's identity and permissions. This affects deployments with JWT/OIDC authentication enabled. Fixed in v1.83.0.
When 'enable_jwt_auth: true' is enabled, the OIDC userinfo cache mechanism uses only the first 20 characters of the token (token[:20]) as the cache key. JWT tokens signed with the same algorithm can generate identical first 20 characters. An attacker can craft a token whose first 20 characters match the token of a legitimate user already in the cache. In case of a cache hit, the attacker assumes the identity and permissions of that user without needing to possess valid credentials.
An attacker gains unauthorized access to resources and functionalities available to a legitimate user, potentially including full control over external systems (SC:H/SI:H) with which LiteLLM integrates as an AI Gateway.
LiteLLM should be updated to version 1.83.0 or later, which fixes the cache key generation mechanism. Until the update is applied, as a workaround, disabling the 'enable_jwt_auth' option can be considered if it is not strictly required.
LiteLLM (product by BerriAI) in versions earlier than 1.83.0, only in configurations with the 'enable_jwt_auth: true' option enabled. This option is not active by default, which limits the scope of the vulnerability.
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XLitellm
APPLitellm< 1.83.0
Related vulnerabilities
SQL Injection w LiteLLM umożliwia nieautoryzowany dostęp do bazy danych
Atak supply chain na Trivy — złośliwe tagi GitHub Actions i obraz kontenera
LiteLLM: pominięcie uwierzytelnienia przez manipulację nagłówkiem Host
RCE w BerriAI/litellm poprzez endpoint /config/update
BerriAI LiteLLM – SSTI via Jinja umożliwia RCE przez endpoint /completions