In berriai/litellm version v1.52.1, an issue in proxyserver.py causes the leakage of Langfuse API keys when an error occurs while parsing team settings. This vulnerability exposes sensitive information, including langfusesecret and langfusepublickey, which can provide full access to the Langfuse project storing all requests.
{ "nvd_published_at": "2025-03-20T10:15:52Z", "cwe_ids": [ "CWE-1230" ], "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2025-03-20T20:59:37Z" }