High severity7.5NVD Advisory· Published Mar 20, 2025· Updated Jun 17, 2026
CVE-2025-0330
CVE-2025-0330
Description
In berriai/litellm version v1.52.1, an issue in proxy_server.py causes the leakage of Langfuse API keys when an error occurs while parsing team settings. This vulnerability exposes sensitive information, including langfuse_secret and langfuse_public_key, which can provide full access to the Langfuse project storing all requests.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
litellmPyPI | <= 1.52.1 | — |
Affected products
3- berriai/berriai/litellmv5Range: unspecified
Patches
Vulnerability mechanics
References
3- huntr.com/bounties/661b388a-44d8-4ad5-862b-4dc5b80be30anvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-879v-fggm-vxw2ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2025-0330ghsaADVISORY
News mentions
0No linked articles in our index yet.