#34451 Security: Follow-up on two zero-auth critical vulnerabilities submitted July 12 via Pylon
Hi @ishaan-jaff @Sameerlite,
On July 12, I submitted two critical security vulnerabilities through the Pylon security intake system:
1. **Guardrail SSRF** (CVSS 8.6) — Zero-authentication exploitable 2. **No-Auth Admin Bypass** (CVSS 8.1) — Zero-authentication exploitable
It has been 12 days with no substantive feedback from the security team. The Pylon ticket was auto-closed due to inactivity, and my follow-up email could not be delivered (DNS resolution failure on service.usepylon.com).
Both vulnerabilities are independently reproducible and have been verified against live LiteLLM instances. I am following responsible disclosure practices and have not published any details.
Could you please: 1. Confirm receipt of these reports 2. Provide a timeline for security team review 3. Let me know if you need me to resubmit through an alternative channel
I can provide full PoC and reproduction steps upon confirmation.
Thank you, Wang Guigui Correctover = AI Reliability™ https://correctover.com