1.84.0.dev1
2 years ago
1 days ago
Known vulnerabilities in the litellm package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for free| Vulnerability | Vulnerable Version |
|---|---|
litellm is a Library to easily interface with LLM API providers Affected versions of this package are vulnerable to SQL Injection via the token lookup query in the combined view path. An attacker can extract or manipulate records by supplying a crafted token value that is interpolated directly into the Workarounds
How to fix SQL Injection? Upgrade | [1.81.16,1.83.7) |
litellm is a Library to easily interface with LLM API providers Affected versions of this package are vulnerable to Improper Neutralization of Special Elements Used in a Template Engine via the How to fix Improper Neutralization of Special Elements Used in a Template Engine? Upgrade | [1.80.5,1.83.7) |
litellm is a Library to easily interface with LLM API providers Affected versions of this package are vulnerable to Command Injection via preview MCP server endpoints How to fix Command Injection? Upgrade | [1.74.2,1.83.7) |
litellm is a Library to easily interface with LLM API providers Affected versions of this package are vulnerable to Arbitrary Code Injection in the How to fix Arbitrary Code Injection? There is no fixed version for | [0,) |