{"data":{"id":"7b90d415-432b-4e75-b43b-e3f66a45eeb6","title":"GHSA-46cm-pfwv-cgf8: LiteLLM has Server-Side Template Injection vulnerability in /completions endpoint","summary":"BerriAI/litellm is vulnerable to Server-Side Template Injection (SSTI) via the `/completions` endpoint. The `hf_chat_template` method passes the `chat_template` parameter from `tokenizer_config.json` through the Jinja template engine without proper sanitization. Attackers can craft malicious `tokenizer_config.json` files to execute arbitrary code on the server.","solution":"N/A -- no mitigation discussed in source.","labels":["security"],"sourceUrl":"https://github.com/advisories/GHSA-46cm-pfwv-cgf8","publishedAt":"2024-04-10T18:30:48.000Z","cveId":"CVE-2024-2952","cweIds":["CWE-76"],"cvssScore":"9.8","cvssSeverity":"critical","severity":"critical","attackType":["other"],"issueType":"vulnerability","affectedPackages":["litellm@< 1.34.42 (fixed: 1.34.42)"],"affectedPackageNames":["litellm"],"affectedPackageRefs":["pypi:litellm"],"affectedVendors":[],"affectedVendorsRaw":["LiteLLM"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","summaryPromptVersion":"v2","headline":null,"headlinePromptVersion":null,"cvssVector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"network","attackComplexity":"low","privilegesRequired":"none","userInteraction":"none","exploitMaturity":"unknown","epssScore":0.01267,"epssCheckedAt":"2026-10-10T04:57:07.145Z","kevDateAdded":null,"advisoryAliases":["GHSA-46cm-pfwv-cgf8"],"affectedPackagesSource":null,"affectedPackagesCheckedAt":null,"patchAvailable":true,"disclosureDate":"2024-04-10T18:30:48.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality","integrity","availability"],"aiComponentTargeted":"api","llmSpecific":true,"classifierConfidence":0.95,"researchCategory":null,"atlasIds":null}}