AI Gateway Compromise: Chained Starlette and LiteLLM Flaws Expose Foundation Model Keys
Threat actors chain Starlette and LiteLLM flaws to achieve unauthenticated RCE and steal enterprise AI keys. Discover key forensic details and patch steps.
Tag archive
Reporting and analysis related to AI Gateway Security.
Threat actors chain Starlette and LiteLLM flaws to achieve unauthenticated RCE and steal enterprise AI keys. Discover key forensic details and patch steps.
CVE-2026-33017 exposes Langflow AI workflow builders to unauthenticated remote code execution through the public flow build endpoint.
Critical LiteLLM CVE-2026-42208 pre-auth SQL injection exposes AI gateway databases, virtual keys and upstream model-provider credentials.