CISA added to the KEV catalog an authentication bypass fault in LiteLLM's MCP module, which has been corrected since May 14. This is the third LiteLLM fault referenced in four months, highlighting the risks associated with LLM proxies that centralize APIs, budgets and access to tools. LiteLLM organizations need to verify the application of patches and enhance the security of these critical gateways.
This story is only covered by news sources that have yet to be evaluated by the independent media monitoring agencies we use to assess the quality and reliability of news outlets on our platform. Learn more here.
CISA added to the KEV catalog an authentication bypass fault in LiteLLM's MCP module, which has been corrected since May 14. This is the third LiteLLM fault referenced in four months, highlighting the risks associated with LLM proxies that centralize APIs, budgets and access to tools. LiteLLM organizations need to verify the application of patches and enhance the security of these critical gateways.