CVE-2025-11203 is an information disclosure vulnerability in LiteLLM affecting the health endpoint. The flaw is in the handling of the API_KEY parameter supplied to that endpoint, which can result in sensitive information being exposed to an unauthorized actor. According to the provided content, a remote attacker with authentication can exploit the issue to disclose stored credentials. The issue was assigned ZDI-CAN-26585.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a self-contained proof-of-concept for CVE-2025-11203, an authenticated information disclosure issue in LiteLLM health endpoints. The main exploit logic is in exploit/exploit.py, a Python script that sends an authenticated GET request to the target /health endpoint using a Bearer token, parses the JSON response, and recursively searches for sensitive fields such as api_key, token, secret, apikey, api-key, and x-api-key. Its core capability is credential extraction from health-check output; it does not provide code execution or shell access. Repository structure is straightforward: README.md documents the vulnerability, usage, and expected output; exploit/exploit.py is the primary exploit entry point; docker-compose.yml provisions both a vulnerable and fixed LiteLLM instance; litellm-vuln/Dockerfile builds a vulnerable LiteLLM 1.61.0 container and deliberately patches /usr/local/lib/python3.11/site-packages/litellm/proxy/health_check.py to remove api_key sanitization; litellm_config.yaml contains three demo model configurations with embedded API keys and a master key; docs/advisory.md summarizes the advisory; screenshots/README.md is placeholder documentation for PoC screenshots. The exploit targets LiteLLM versions prior to 1.63.14, specifically demonstrating leakage via GET /health. The included lab environment exposes the vulnerable service on localhost:4000 and a fixed comparison instance on localhost:4001. Successful exploitation requires a valid LiteLLM API/master key and a target configured with upstream model credentials. When successful, the script reports leaked credentials and counts configured healthy/unhealthy endpoints, confirming exposure of stored provider API keys from model configuration.
2 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.