Information Disclosure Vulnerability in LiteLLM by Vendor
CVE-2025-11203

3.5LOW

Key Information:

Vendor

Litellm

Status
Vendor
CVE Published:
29 October 2025

What is CVE-2025-11203?

The vulnerability during the handling of the API_KEY parameter in the health endpoint of LiteLLM allows remote attackers to gain unauthorized access to sensitive information. Exploitation of this flaw requires authentication but can lead to the disclosure of stored credentials within affected installations. By leveraging this vulnerability, attackers may further compromise systems and access confidential data. For more details, visit the advisories linked below.

Affected Version(s)

LiteLLM 10.2.2025

References

CVSS V3.0

Score:
3.5
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-11203 : Information Disclosure Vulnerability in LiteLLM by Vendor