GHSA-fx43-jvpp-9x44MediumCVSS 5.3

OpenLIT 2.1.0 contains an authorization bypass vulnerability that allows authenticated users to...

Published
October 10, 2026
Last Modified
October 10, 2026

🔗 CVE IDs covered (1)

📋 Description

OpenLIT 2.1.0 contains an authorization bypass vulnerability that allows authenticated users to read other projects' telemetry by supplying a forged x-openlit-project-id header. Attackers who know a victim project id and database config id can query the trace read API to obtain traces including LLM prompts and completions.

🔗 References (7)