Vendor
Katanemo Plano versions 0.4.37 and earlier contain a missing authentication vulnerability on the Envoy admin interface that allows unauthenticated remote attackers to exfiltrate LLM provider API keys.