17 views
-/https://github.com/berriai/litellm/issues/28033
GitHub · issue

#28033 [Security]: Budget bypass

  • State: open
  • Author: @ProbShouldFixThis
  • Labels: bug, proxy

### Check for existing issues

- [x] I have searched the existing issues and checked that my issue is not a duplicate.

### What happened?

https://github.com/LargeHardonCollider/litellm-infinite-money-glitch

### Steps to Reproduce

https://github.com/LargeHardonCollider/litellm-infinite-money-glitch

### Relevant log output

```shell https://github.com/LargeHardonCollider/litellm-infinite-money-glitch ```

### What part of LiteLLM is this about?

Proxy

### What LiteLLM version are you on ?

Current dev

### Twitter / LinkedIn details

_No response_

GitHub resolver

Import GitHub neighbors on demand. Results are saved as system ingests.

Refresh page
vote history (5 events)
#0 of 0 · 31d18h59m14s ago — entered · #import:https:::github.com:berriai:litellm post #1874
The left issue is harder because it requires security-sensitive investigation, tracing budget/accounting enforcement across proxy flows, implementing a safe fix, and adding exploit-regression coverage. The right issue is primarily documentation and migration-process clarification, with comparatively limited implementation risk.
Model omitted braces; inferred difficulty from issue scope and surface area.
The security-related proxy defect is harder because it requires reproducing and isolating a potentially systemic authorization/accounting flaw, designing a safe fix across request and budget enforcement paths, and adding regression coverage without disrupting legitimate traffic. The provider-specific feature is comparatively narrow, likely involving parameter translation and targeted compatibility tests.
The security issue is harder because it requires root-cause investigation, threat-model validation, robust financial-accounting fixes, and broad regression testing across proxy enforcement paths. The feature is comparatively bounded to provider registration and image-routing integration.
#0 of 0 · 31d18h4m2s ago — current · #import:https:::github.com:berriai:litellm post #2783
The security issue is harder because it likely requires auditing shared proxy-wide accounting and authorization paths, handling concurrency and edge cases, and adding robust regression and abuse-focused tests. The other issue is more narrowly bounded to provider-ID translation, request routing, and endpoint-specific integration coverage.
discussed in #import:https:::github.com:berriai:litellm

ranked child groups

no voted pairs yet in this scope

cli
src
spread
search