6 views
-/https://github.com/berriai/litellm/issues/34451
GitHub · issue

#34451 Security: Follow-up on two zero-auth critical vulnerabilities submitted July 12 via Pylon

  • State: open
  • Author: @Correctover

Hi @ishaan-jaff @Sameerlite,

On July 12, I submitted two critical security vulnerabilities through the Pylon security intake system:

1. **Guardrail SSRF** (CVSS 8.6) — Zero-authentication exploitable 2. **No-Auth Admin Bypass** (CVSS 8.1) — Zero-authentication exploitable

It has been 12 days with no substantive feedback from the security team. The Pylon ticket was auto-closed due to inactivity, and my follow-up email could not be delivered (DNS resolution failure on service.usepylon.com).

Both vulnerabilities are independently reproducible and have been verified against live LiteLLM instances. I am following responsible disclosure practices and have not published any details.

Could you please: 1. Confirm receipt of these reports 2. Provide a timeline for security team review 3. Let me know if you need me to resubmit through an alternative channel

I can provide full PoC and reproduction steps upon confirmation.

Thank you, Wang Guigui Correctover = AI Reliability™ https://correctover.com

GitHub resolver

Import GitHub neighbors on demand. Results are saved as system ingests.

Refresh page
vote history (4 events)
#0 of 0 · 31d19h5m18s ago — entered · #import:https:::github.com:berriai:litellm post #1778
Security work carries substantially higher engineering risk due to exploit validation, remediation across authentication and request-routing boundaries, regression testing, and coordinated disclosure. The model-integration request is narrower, largely involving provider configuration, capability mapping, and targeted tests.
The right item requires coordinated investigation and remediation across multiple security-sensitive execution paths, with substantial validation and regression risk. The left item is a localized query-condition correction with comparatively narrow scope.
The security work carries substantially greater scope and risk: it requires vulnerability triage, threat modeling, coordinated remediation, and careful regression validation across exposed proxy surfaces. The other issue is comparatively localized to provider routing and endpoint-selection behavior.
#0 of 0 · 31d18h53m25s ago — current · #import:https:::github.com:berriai:litellm post #1982
The right issue is harder because it requires security triage, coordinated validation, and potentially broad changes across authorization and network-boundary controls; the left is comparatively localized to async lifecycle handling with focused tests.
discussed in #import:https:::github.com:berriai:litellm

ranked child groups

no voted pairs yet in this scope

cli
src
spread
search