Indie app developer Alex Nguyen, creator of AI tool Notewave.app, accused a Vietnamese builder of copying his app after sharing marketing tactics during a private coffee meeting. Following the incident, Nguyen stopped offering one-on-one mentoring sessions to protect his strategies, though he continues sharing publicly across multiple channels. The case highlights tensions in the indie hacker community between building in public for growth and protecting intellectual property from copycats.
LiteLLM contains a privilege escalation vulnerability where authenticated internal users can escalate to proxy admin and achieve remote code execution by exploiting cross-domain reuse of encryption keys. An attacker crafts a forged admin credential in API key metadata that the proxy encrypts and then trusts when presented as a bearer token, granting full administrative access including command execution.