VulnSea

litellm vulnerabilities

CVEs whose affected-version data names the litellm package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

39 CVEsRSS

CVE-2024-6825High· 8.8
1y ago

LiteLLM Vulnerable to Remote Code Execution (RCE)

LiteLLM Vulnerable to Remote Code Execution (RCE)

Twilightlitellm · litellmEPSS 1.7%via OSV
CVE-2024-6587High· 7.5PoC
2y ago

LiteLLM Server-Side Request Forgery (SSRF) vulnerability

LiteLLM Server-Side Request Forgery (SSRF) vulnerability

Midnightlitellm · litellmEPSS 35%via OSV
CVE-2024-5751Critical· 9.8PoC
2y ago

BerriAI/litellm version v1.35.8 contains a vulnerability where an attacker can achieve remote code execution

BerriAI/litellm version v1.35.8 contains a vulnerability where an attacker can achieve remote code execution. The vulnerability exists in the `add_deployment` function, which decodes and decrypts environment variables from base64 and ass…

Abyssallitellm · litellmEPSS 0.88%via NVD
CVE-2024-5710Medium· 5.3
2y ago

litellm vulnerable to improper access control in team management

litellm vulnerable to improper access control in team management

Sunlitlitellm · litellmEPSS 0.41%via OSV
CVE-2024-5225Medium· 6.4
2y ago

SQL injection in litellm

SQL injection in litellm

Sunlitlitellm · litellmEPSS 0.43%via OSV
CVE-2024-4890Medium· 4.9PoC
2y ago

SQL injection in litellm

SQL injection in litellm

Twilightlitellm · litellmEPSS 0.56%via OSV
CVE-2024-4888Medium· 6.5
2y ago

Arbitrary file deletion in litellm

Arbitrary file deletion in litellm

Sunlitlitellm · litellmEPSS 0.62%via OSV
CVE-2024-4264High· 7.2
2y ago

litellm passes untrusted data to `eval` function without sanitization

litellm passes untrusted data to `eval` function without sanitization

Twilightlitellm · litellmEPSS 0.88%via OSV
CVE-2024-2952Critical· 9.8
2y ago

LiteLLM has Server-Side Template Injection vulnerability in /completions endpoint

LiteLLM has Server-Side Template Injection vulnerability in /completions endpoint

Midnightlitellm · litellmEPSS 1.3%via OSV
litellm vulnerabilities (CVEs) — page 2 · VulnSea