LiteLLM contains a privilege escalation vulnerability where authenticated internal users can escalate to proxy admin and achieve remote code execution by exploiting cross-domain reuse of encryption keys. An attacker crafts a forged admin credential in API key metadata that the proxy encrypts and then trusts when presented as a bearer token, granting full administrative access including command execution.