SQL Injection Affecting litellm package, versions [,1.40.0)
Threat Intelligence
Exploit Maturity
Proof of concept
EPSS
0.05% (21st
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-PYTHON-LITELLM-7218855
- published 7 Jun 2024
- disclosed 6 Jun 2024
- credit CodeVigilante
How to fix?
Upgrade litellm
to version 1.40.0 or higher.
Overview
litellm is a Library to easily interface with LLM API providers
Affected versions of this package are vulnerable to SQL Injection through the /global/spend/logs
endpoint. An authenticated attacker can manipulate data and potentially gain unauthorized access by injecting malicious SQL commands into the api_key
parameter.
References
CVSS Scores
version 3.1