CVE-2025-0330
CVSS 3.0 Score 7.5 of 10 (high)
Details
Published Mar 20, 2025
CWE ID 1230
Summary
CVE-2025-0330 is a vulnerability affecting berriai/litellm version 1.52.1. In this case, an issue with proxy_server.py leads to the leakage of Langfuse API keys. These keys, which include the sensitive information langfuse_secret and langfuse_public_key, are exposed when an error occurs during team settings parsing. Attackers can exploit this vulnerability to gain full access to the Langfuse project, storing all requests, putting sensitive data at risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- BerriAI LiteLLM