Authorization bypass through user-controlled key in Tolgee - #VU133246
Published: June 2, 2026
Tolgee
Detailed vulnerability description
The vulnerability allows a remote user to modify another organization's LLM provider configuration and redirect future LLM traffic.
The vulnerability exists due to authorization bypass through user-controlled key in the LLM provider update endpoint when handling update requests with a foreign provider identifier under an authorized organization URL. A remote user can send a specially crafted request to modify another organization's LLM provider configuration and redirect future LLM traffic.