Nearly 1 in 10 LiteLLM Gateways Exposed Default Key
🔒 Wiz Research found that many internet-facing LiteLLM gateways still accept the example admin key sk-1234 from the setup guide, allowing full admin access. The master key controls admin rights and authentication; if left default or unset, attackers can retrieve provider API keys and potentially cloud IAM credentials via pass-through endpoints. Several CVEs affecting guardrails, MCP authentication, and sandbox escapes have been fixed in recent releases, and upgrades plus key rotation are recommended.
