litellm vulnerabilities
CVEs whose affected-version data names the litellm package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
39 CVEsRSS
CVE-2024-6825High· 8.8LiteLLM Vulnerable to Remote Code Execution (RCE)
LiteLLM Vulnerable to Remote Code Execution (RCE)
CVE-2024-6587High· 7.5PoCLiteLLM Server-Side Request Forgery (SSRF) vulnerability
LiteLLM Server-Side Request Forgery (SSRF) vulnerability
CVE-2024-5751Critical· 9.8PoCBerriAI/litellm version v1.35.8 contains a vulnerability where an attacker can achieve remote code execution
BerriAI/litellm version v1.35.8 contains a vulnerability where an attacker can achieve remote code execution. The vulnerability exists in the `add_deployment` function, which decodes and decrypts environment variables from base64 and ass…
CVE-2024-5710Medium· 5.3litellm vulnerable to improper access control in team management
litellm vulnerable to improper access control in team management
CVE-2024-5225Medium· 6.4SQL injection in litellm
SQL injection in litellm
CVE-2024-4890Medium· 4.9PoCSQL injection in litellm
SQL injection in litellm
CVE-2024-4888Medium· 6.5Arbitrary file deletion in litellm
Arbitrary file deletion in litellm
CVE-2024-4264High· 7.2litellm passes untrusted data to `eval` function without sanitization
litellm passes untrusted data to `eval` function without sanitization
CVE-2024-2952Critical· 9.8LiteLLM has Server-Side Template Injection vulnerability in /completions endpoint
LiteLLM has Server-Side Template Injection vulnerability in /completions endpoint