Medium severity5.3NVD Advisory· Published Oct 10, 2026
CVE-2026-108596
CVE-2026-108596
Description
OpenLIT 2.1.0 contains an authorization bypass vulnerability that allows authenticated users to read other projects' telemetry by supplying a forged x-openlit-project-id header. Attackers who know a victim project id and database config id can query the trace read API to obtain traces including LLM prompts and completions.
Affected products
1Patches
Vulnerability mechanics
References
4- github.com/openlit/openlit/blob/9938c66638666ca5d3bcb850350faa82e510924b/src/client/src/lib/telemetry-source.tsnvd
- github.com/openlit/openlit/blob/9938c66638666ca5d3bcb850350faa82e510924b/src/client/src/middleware/check-auth.tsnvd
- hackmd.io/@haind/openlit-project-context-readnvd
- www.vulncheck.com/advisories/openlit-2.1.0-authorization-bypass-via-x-openlit-project-id-headernvd
News mentions
0No linked articles in our index yet.