VYPR
High severity7.5NVD Advisory· Published Mar 20, 2025· Updated Jun 17, 2026

CVE-2024-9606

CVE-2024-9606

Description

In berriai/litellm before version 1.44.12, the litellm/litellm_core_utils/litellm_logging.py file contains a vulnerability where the API key masking code only masks the first 5 characters of the key. This results in the leakage of almost the entire API key in the logs, exposing a significant amount of the secret key. The issue affects version v1.44.9.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
litellmPyPI
< 1.44.121.44.12

Affected products

3
  • berriai/berriai/litellmv5
    Range: unspecified
  • ghsa-coords
    Range: < 1.44.12
  • cpe:2.3:a:litellm:litellm:*:*:*:*:*:*:*:*
    Range: <1.44.12

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.