CVE-2025-0330
HIGHDescription
In berriai/litellm version v1.52.1, an issue in proxy_server.py causes the leakage of Langfuse API keys when an error occurs while parsing team settings. This vulnerability exposes sensitive information, including langfuse_secret and langfuse_public_key, which can provide full access to the Langfuse project storing all requests.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| litellm | litellm |
References
Frequently Asked Questions
What is CVE-2025-0330? +
How severe is CVE-2025-0330? +
What products are affected by CVE-2025-0330? +
How do I check if I'm vulnerable to CVE-2025-0330? +
Related Vulnerabilities
The vulnerability consists of a session ID leak when saving a file downloaded from CGM CLININET. The identifier is exposed …
In lunary-ai/lunary version v1.4.29, the GET /projects API endpoint exposes both public and private API keys for all projects to …
The users endpoint in the groov View API returns a list of all users and associated metadata including their API …
Information disclosure while accessing and modifying the PIB file of a remote device via powerline.
Dell NativeEdge, version(s) 2.1.0.0, contain(s) an Exposure of Sensitive Information Through Metadata vulnerability. An unauthenticated attacker with remote access could …
Expired and unusable administrator authentication tokens can be revealed by units that have timed out from ETM access