Security: theopenco/llmgateway
Security
No security policy detected
This project has not set up a SECURITY.md file yet.
Report a vulnerability-
Streaming Abort Billing Bypass Allows Authenticated Users to Obtain Unbilled LLM OutputGHSA-724j-f2pf-phf7 published
Jul 31, 2026 by steebchenHigh -
MCP /mcp endpoint accepts unvalidated API keysGHSA-8h26-h6v8-f9cg published
Jun 30, 2026 by steebchenLow -
Tenant-Controlled Provider Base URL SSRFGHSA-8xr7-xg68-p8c5 published
Jun 18, 2026 by steebchenHigh -
Server-Side Request Forgery via custom-provider baseUrl (any org member)GHSA-3r2h-6gmc-w7c2 published
Jun 18, 2026 by steebchenHigh
Learn more about advisories related to theopenco/llmgateway in the GitHub Advisory Database