CVE-2025-0330

Source
https://cve.org/CVERecord?id=CVE-2025-0330
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-0330.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-0330
Aliases
Published
2025-03-20T10:09:34.164Z
Modified
2026-07-15T01:48:58.708975473Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
Exposure of Sensitive Information in berriai/litellm
Details

In berriai/litellm version v1.52.1, an issue in proxyserver.py causes the leakage of Langfuse API keys when an error occurs while parsing team settings. This vulnerability exposes sensitive information, including langfusesecret and langfusepublickey, which can provide full access to the Langfuse project storing all requests.

Database specific
{
    "cna_assigner": "@huntr_ai",
    "cwe_ids": [
        "CWE-1230"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/0xxx/CVE-2025-0330.json"
}
References

Affected packages

Git / github.com/berriai/litellm

Affected ranges

Type
GIT
Repo
https://github.com/berriai/litellm
Events
Database specific
{
    "cpe": "cpe:2.3:a:litellm:litellm:1.52.1:-:*:*:*:*:*:*",
    "source": "CPE_STRING",
    "extracted_events": [
        {
            "introduced": "1.52.1-NA"
        },
        {
            "last_affected": "1.52.1-NA"
        }
    ]
}

Affected versions

1.*
1.52.1-NA
v1.*
v1.52.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-0330.json"