LiteLLM: an ordinary login token can become someone else’s admin account

LiteLLM Account takeover
Share

More details to come soon

LiteLLM is an open-source gateway used by companies to manage access to OpenAI, Anthropic, and other LLM APIs. It holds API keys, tracks spend, and controls who can access what.

We found a way to use a legitimately signed login token to authenticate as another existing LiteLLM user, including an admin.

The issue: when LiteLLM receives a JWT it doesn’t recognize, it falls back to matching the token’s email against an existing account. It does not verify that the email was actually validated by the token issuer.

That means an attacker who obtains a valid, signed token containing an existing admin’s email address can be treated as that admin.

Nothing is forged. Nothing is cryptographically broken, and the token is valid. LiteLLM simply trusts the wrong identity.

More details soon.

Tags:

OX cloud 1

Active AI Defense. Complete Cloud Visibility.

Your agents hold identities you never issued. See what they touch, in real time.

Meet OX Cloud