people · May 17, 2026
LiteLLM Exploited at Pwn2Own Berlin 2026 via SSRF and Code Injection Chain
Share the canonical public link.
Researchers at Pwn2Own Berlin 2026 compromised LiteLLM on May 15, 2026. Researcher k3vg3n chained SSRF and code injection bugs to take control of the AI gateway proxy. LiteLLM routes requests to over 100 LLM providers including OpenAI and Anthropic while centralizing API keys. The event also featured exploits against Microsoft Edge, Windows 11, and NVIDIA platforms on the same day.
Spend governor blocked model creation: provider_circuit_open (lane=dev, provider=together)