NewsSecurity
Your AI tools hold the keys. Attackers have noticed.
A flaw in LiteLLM, a popular gateway for AI models and agents, is being used in real attacks. It is a reminder of what sits inside the plumbing of every AI system.
On 2 September, the US Cybersecurity and Infrastructure Security Agency (CISA) added seven vulnerabilities to its catalogue of flaws known to be exploited in the wild. One of them, CVE-2026-59822, is an authentication bypass in LiteLLM, open-source software many teams use to route requests to AI models and to the tools their agents connect to.
Reports on the flaw describe attackers using crafted tokens to get past LiteLLM's key checks, reach its connected tools and pull out the provider keys the gateway stores. The same CISA update listed a request-smuggling flaw in Starlette, a Python web framework, which researchers say was chained with it.
Why the plumbing matters
An AI gateway is convenient because it keeps everything in one place: the keys for every model provider, the settings for every agent, and the connections to the email, files or databases those agents can use. That is exactly what makes it valuable to an attacker. One exposed gateway can mean stolen keys, a surprise bill, and an agent quietly doing someone else's work.
What to check this week
- Find every AI gateway, proxy or agent server you run (including the one a developer set up to try something) and patch it or switch it off.
- Keep admin and management endpoints off the public internet.
- Rotate any provider keys an exposed system could have read, and set spending limits with each provider.
- Give each agent the fewest permissions it needs, and log what it does.
- Ask any vendor running AI on your behalf how they handle the same risks.








