1.102.0.dev2
3 years ago
1 days ago
Known vulnerabilities in the litellm package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for free| Vulnerability | Vulnerable Version |
|---|---|
litellm is a Library to easily interface with LLM API providers Affected versions of this package are vulnerable to Server-side Request Forgery (SSRF) through request-body validation in the proxy auth path. An authenticated user can supply routing or credential parameters such as How to fix Server-side Request Forgery (SSRF)? Upgrade | [,1.88.6)[1.89.0rc1,1.89.7)[1.90.0rc1,1.90.7)[1.91.0rc1,1.91.5)[1.92.0rc1,1.92.2)[1.93.0rc1,1.93.2)[1.94.0rc1,1.94.3)[1.95.0rc1,1.95.1)[1.96.0rc1,1.96.2) |
litellm is a Library to easily interface with LLM API providers Affected versions of this package are vulnerable to Insufficient Session Expiration in the How to fix Insufficient Session Expiration? There is no fixed version for | [0,) |
litellm is a Library to easily interface with LLM API providers Affected versions of this package are vulnerable to Missing Authentication for Critical Function in the How to fix Missing Authentication for Critical Function? There is no fixed version for | [0,) |
litellm is a Library to easily interface with LLM API providers Affected versions of this package are vulnerable to Insufficient Session Expiration in the How to fix Insufficient Session Expiration? There is no fixed version for | [0,) |