{"data":{"id":"16367f09-a707-4eaa-b63d-2c1a56265bbe","title":"GHSA-8j42-pcfm-3467: SQL injection in litellm","summary":"A blind SQL injection vulnerability in the berriai/litellm application affects the '/team/update' process. The flaw stems from improper handling of the 'user_id' parameter in a raw SQL query used to delete users, letting an attacker inject SQL through that parameter. The affected version is 1.27.14.","solution":"N/A -- no mitigation discussed in source.","labels":["security"],"sourceUrl":"https://github.com/advisories/GHSA-8j42-pcfm-3467","publishedAt":"2024-06-06T21:30:37.000Z","cveId":"CVE-2024-4890","cweIds":["CWE-89"],"cvssScore":"4.9","cvssSeverity":"medium","severity":"medium","attackType":["other"],"issueType":"vulnerability","affectedPackages":["litellm@<= 1.27.14"],"affectedPackageNames":["litellm"],"affectedPackageRefs":["pypi:litellm"],"affectedVendors":[],"affectedVendorsRaw":["LiteLLM"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","summaryPromptVersion":"v2","headline":null,"headlinePromptVersion":null,"cvssVector":"CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N","attackVector":"network","attackComplexity":"low","privilegesRequired":"high","userInteraction":"none","exploitMaturity":"unknown","epssScore":0.0056,"epssCheckedAt":"2026-10-10T04:57:08.845Z","kevDateAdded":null,"advisoryAliases":["GHSA-8j42-pcfm-3467"],"affectedPackagesSource":null,"affectedPackagesCheckedAt":null,"patchAvailable":null,"disclosureDate":"2024-06-06T21:30:37.000Z","capecIds":["CAPEC-66"],"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality"],"aiComponentTargeted":"api","llmSpecific":true,"classifierConfidence":0.9,"researchCategory":null,"atlasIds":null}}