Skip to main content

System status

Coverage is stale.

Collection is paused. Latest public event: Aug 21, 2026 (10 days ago).

← Intel index

This coverage is stale.

Last updated May 17, 2026 (about 4 months ago).

people · May 17, 2026

LiteLLM Exploited at Pwn2Own Berlin 2026 via SSRF and Code Injection Chain

Share the canonical public link.

Share as image

Researchers at Pwn2Own Berlin 2026 compromised LiteLLM on May 15, 2026. Researcher k3vg3n chained SSRF and code injection bugs to take control of the AI gateway proxy. LiteLLM routes requests to over 100 LLM providers including OpenAI and Anthropic while centralizing API keys. The event also featured exploits against Microsoft Edge, Windows 11, and NVIDIA platforms on the same day.

Spend governor blocked model creation: provider_circuit_open (lane=dev, provider=together)

Supporting evidence