Over 39,000 LiteLLM AI Gateway Deployments Exposed on Public Internet
A ZoomEye scan has identified 39,155 internet-facing assets matching LiteLLM fingerprints, with the largest concentrations in the United States, China, Japan, India, and Australia. LiteLLM is an AI gateway proxy that stores API keys for multiple model providers like OpenAI and Anthropic, making it a high-value target if compromised. A vulnerability in certain LiteLLM releases allowed any valid low-privilege key to execute arbitrary commands with proxy-level privileges, bypassing role checks entirely. Security researchers note that AI gateway infrastructure has rapidly moved from experimental to production use without adequate exposure management practices catching up. Organizations running LiteLLM are advised to upgrade to at least version 1.83.7 and audit whether their deployments are publicly reachable.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in