GHSA-fx43-jvpp-9x44MediumCVSS 5.3
OpenLIT 2.1.0 contains an authorization bypass vulnerability that allows authenticated users to...
🔗 CVE IDs covered (1)
📋 Description
OpenLIT 2.1.0 contains an authorization bypass vulnerability that allows authenticated users to read other projects' telemetry by supplying a forged x-openlit-project-id header. Attackers who know a victim project id and database config id can query the trace read API to obtain traces including LLM prompts and completions.
🔗 References (7)
- https://nvd.nist.gov/vuln/detail/CVE-2026-108596
- https://github.com/openlit/openlit
- https://github.com/openlit/openlit/blob/9938c66638666ca5d3bcb850350faa82e510924b/src/client/src/lib/telemetry-source.ts#L113-L125
- https://github.com/openlit/openlit/blob/9938c66638666ca5d3bcb850350faa82e510924b/src/client/src/middleware/check-auth.ts#L22-L33
- https://hackmd.io/@haind/openlit-project-context-read
- https://www.vulncheck.com/advisories/openlit-2.1.0-authorization-bypass-via-x-openlit-project-id-header
- https://github.com/advisories/GHSA-fx43-jvpp-9x44