Malicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organizations
Two malicious LiteLLM releases on PyPI, versions 1.82.7 and 1.82.8, were live for about 40 minutes on March 24, 2026, carrying credential-stealing…
Two malicious LiteLLM releases on PyPI, versions 1.82.7 and 1.82.8, were live for about 40 minutes on March 24, 2026, carrying credential-stealing…
A chain of three vulnerabilities in LiteLLM, a widely deployed open-source AI gateway, allows low-privilege users to escalate to full admin and…
BerriAI is the company behind the LiteLLM project. It was involved in responding to the malicious releases, with its incident report pointing…
BerriAI LiteLLM Command Injection Vulnerability Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of…
BerriAI LiteLLM SQL Injection Vulnerability Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of…