Vulnerability  ·  2026-10-11

OpenLIT 2.1.0: forged x-openlit-project-id header lets authenticated users read other projects' LLM traces/prompts (CVSS 5.3)

VulnerabilityHigh impactGlobalCVE-2026-108596
Verified via NVD REST API (published 2026-10-10, VulnCheck). The telemetry source in the client picks the project via the header and the auth middleware only checks that a valid project context exists, not ownership.
LLM observability data is highly sensitive (prompts/completions contain business data and system instructions); cross-project access defeats the isolation that telemetry platforms must guarantee and can leak prompt content across tenants.
The trace read API trusts the client-supplied x-openlit-project-id header without verifying the caller belongs to that project (CWE-639), so an authenticated attacker forges the header to obtain traces containing LLM prompts, completions and potentially embedded data.
openlit/openlit 2.1.0
Upgrade to the fixed release (auth middleware now derives the project from the session, not the header); ensure database config IDs are not guessable. See VulnCheck advisory.
NVD CVE-2026-108596NVD REST APIVulnCheck advisory
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →