Official company update
CVE-2026-93355: Account Takeover in LiteLLM
OX Security·ox.security·
What the source says
One request carrying an unverified email claim grants immediate access as the victim and permanently mutates account TL;DR What: OX Research found a way to use a legitimately signed login token to authenticate as another existing LiteLLM user, including an admin. LiteLLM is an open-source gateway used by companies to manage access to OpenAI, Anthropic, [R
Checking access…
The original publication, including any images and updates, remains with the publisher.
Checking free source access…
More about OX Security
Official · ox.security“Shai-Hulud: Here We Go Again” – “tensorlake” npm Package Hit With MalwareOfficial · ox.securitySSRF in Harbor Webhooks: Any User Can Reach the Server’s Cloud CredentialsOfficial · ox.securityPhantomSub: Malicious npm Campaign Secretly Adds Users to WhatsApp Spam ChannelsOfficial · ox.securityHow MCP Is Bypassing a Decade of Cloud Security Best Practices