Information Disclosure Vulnerability in LiteLLM by Vendor
CVE-2025-11203
3.5LOW
What is CVE-2025-11203?
The vulnerability during the handling of the API_KEY parameter in the health endpoint of LiteLLM allows remote attackers to gain unauthorized access to sensitive information. Exploitation of this flaw requires authentication but can lead to the disclosure of stored credentials within affected installations. By leveraging this vulnerability, attackers may further compromise systems and access confidential data. For more details, visit the advisories linked below.
Affected Version(s)
LiteLLM 10.2.2025
