Horizon Alert
Summary of the vulnerability and why it matters
A vulnerability has been identified in LiteLLM, an AI gateway proxy, that could allow unauthenticated access to its MCP tooling. This occurs when a crafted authorization header bypasses key validation, potentially exposing sensitive operations. The main concern is to confirm if this technology is in use and if it is exposed externally.
- Unauthorized access to AI gateway tooling.
- Affects systems acting as AI proxies.
- Confirm relevance and external exposure.
Attack Path
How an attacker could exploit the issue
An attacker could exploit this vulnerability by sending a specially crafted request to the LiteLLM proxy server's MCP Streamable HTTP endpoint. This request would manipulate the Authorization header to bypass LiteLLM's key validation, allowing it to proceed without a proper key. This could enable unauthorized access to internal tooling.
- Unauthenticated network access required.
- Fabricated Authorization header triggers fallback.
- Unauthorized access to internal tooling.
Live Threat
Current exploitation, exposure, and threat context
LiteLLM's MCP Streamable HTTP endpoint, when improperly configured, could allow unauthenticated requests to bypass authentication checks and reach its internal tooling. This could occur when the system fails to properly validate a LiteLLM API key, enabling an attacker to send a fabricated Authorization header to trigger an OAuth2 passthrough, thereby replacing the necessary key validation with an empty object.
- Unauthorized access to tooling.
- Malicious headers bypass authentication.
- Compromised service integrity.
Operational Fix
Recommended remediation, mitigation, and detection steps
The LiteLLM proxy server, specifically its MCP Streamable HTTP endpoint, is susceptible to unauthenticated access due to a flaw in its OAuth2 passthrough. Teams responsible for AI infrastructure, API gateways, or applications leveraging LLMs should prioritize identifying all instances of LiteLLM. Confirming their exposure, business criticality, and the accountable owner is the crucial first step before planning remediation.
- Application or platform owners should address this.
- Verify LiteLLM instances and their reachability.
- Plan updates based on risk and operational needs.