What happened
Verified via NVD REST API (published 2026-10-10, VulnCheck). The telemetry source in the client picks the project via the header and the auth middleware only checks that a valid project context exists, not ownership.
Why it matters
LLM observability data is highly sensitive (prompts/completions contain business data and system instructions); cross-project access defeats the isolation that telemetry platforms must guarantee and can leak prompt content across tenants.
Attack vector
The trace read API trusts the client-supplied x-openlit-project-id header without verifying the caller belongs to that project (CWE-639), so an authenticated attacker forges the header to obtain traces containing LLM prompts, completions and potentially embedded data.
Affected systems
openlit/openlit 2.1.0
Mitigation
Upgrade to the fixed release (auth middleware now derives the project from the session, not the header); ensure database config IDs are not guessable. See VulnCheck advisory.