Skip to content

LiteLLM vulnerabilities

LiteLLM appears in the context of a supply chain attack. Reports indicate that the LiteLLM platform was compromised via the Trivy hack, with malicious information-stealing code distributed to users through compromised PyPI versions v1.82.7 and v1.82.8. Over 2,500 organizations were potentially impacted by this incident. Defenders should immediately remove these specific versions and strengthen supply chain security monitoring.

Azərbaycanca: LiteLLM, tədarük zəncirinə qarşı hücum kontekstində qeyd olunur. Hesabatlara əsasən, LiteLLM platforması Trivy adlı vasitə ilə kompromatə olunaraq, onun PyPI v1.82.7 və v1.82.8 versiyaları vasitəsilə istifadəçilərə məlumat oğurlayan zərərli proqram yayılıb. Bu insident nəticəsində 2500-dən çox təşkilat potensial təsirə məruz qalıb. Müdafiəçilər bu versiyaların istifadəsini dərhal dayandırmalı və tədarük zəncirinə qarşı monitorinqi gücləndirməlidir.

This hub is built from skopnix's own reporting on LiteLLM: the overview is AI-written from that coverage and every CVE links to its grounded explainer. KEV status comes from CISA's Known Exploited Vulnerabilities catalog and EPSS from FIRST — vendor, version and score details are never invented.