📦 Litellm

by Litellm

🔍 What is Litellm?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-5751

CRITICAL CVSS 9.8 Jun 27, 2024

This vulnerability allows remote code execution in BerriAI/litellm when an attacker sends a malicious payload to the /config/update endpoint. The vulnerability occurs when environment variables are im...

CVE-2025-0330

HIGH CVSS 7.5 Mar 20, 2025

This vulnerability in berriai/litellm's proxy server leaks Langfuse API keys when team settings parsing fails, exposing sensitive credentials. Attackers gaining these keys can access the Langfuse proj...

CVE-2024-9606

HIGH CVSS 7.5 Mar 20, 2025

This vulnerability in berriai/litellm's logging function only masks the first 5 characters of API keys, exposing nearly the entire secret key in application logs. Any system running affected versions ...

CVE-2024-8984

HIGH CVSS 7.5 Mar 20, 2025

This vulnerability allows unauthenticated attackers to cause a Denial of Service (DoS) by sending specially crafted HTTP requests with appended characters in multipart boundaries, leading to excessive...

CVE-2024-6825

HIGH CVSS 8.8 Mar 20, 2025

This vulnerability in BerriAI/litellm allows remote code execution by exploiting improper input validation in the 'post_call_rules' configuration. Attackers can inject system commands that execute whe...

CVE-2024-6587

HIGH CVSS 7.5 Sep 13, 2024

This SSRF vulnerability in berriai/litellm allows attackers to redirect API requests to malicious servers, exposing OpenAI API keys. Any application using the vulnerable version of litellm with user-c...

CVE-2024-5225

HIGH CVSS 7.2 Jun 6, 2024

An SQL injection vulnerability in the berriai/litellm repository allows attackers to execute arbitrary SQL commands via the /global/spend/logs endpoint by manipulating the api_key parameter. This affe...

CVE-2024-4890

MEDIUM CVSS 4.9 Jun 6, 2024

A blind SQL injection vulnerability in berriai/litellm's '/team/update' endpoint allows attackers to inject malicious SQL through the 'user_id' parameter. This could lead to unauthorized access to sen...