{"data":{"id":"94f9dc17-aa5b-4ccc-a34e-3b280e14ed78","title":"GHSA-7ggm-4rjg-594w: litellm passes untrusted data to `eval` function without sanitization","summary":"A remote code execution flaw in berriai/litellm stems from unsafe use of the `eval` function in the `litellm.get_secret()` method. When the server uses Google KMS, untrusted data reaches `eval` without sanitization. Attackers can inject malicious values into environment variables through the `/config/update` endpoint, which updates settings in `proxy_server_config.yaml`.","solution":"N/A -- no mitigation discussed in source.","labels":["security"],"sourceUrl":"https://github.com/advisories/GHSA-7ggm-4rjg-594w","publishedAt":"2024-05-18T00:30:42.000Z","cveId":"CVE-2024-4264","cweIds":["CWE-94"],"cvssScore":"7.2","cvssSeverity":"high","severity":"high","attackType":["other"],"issueType":"vulnerability","affectedPackages":["litellm@<= 1.28.11"],"affectedPackageNames":["litellm"],"affectedPackageRefs":["pypi:litellm"],"affectedVendors":[],"affectedVendorsRaw":["LiteLLM"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","summaryPromptVersion":"v2","headline":null,"headlinePromptVersion":null,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","attackVector":"network","attackComplexity":"low","privilegesRequired":"high","userInteraction":"none","exploitMaturity":"unknown","epssScore":0.00883,"epssCheckedAt":"2026-10-10T04:57:08.246Z","kevDateAdded":null,"advisoryAliases":["GHSA-7ggm-4rjg-594w"],"affectedPackagesSource":null,"affectedPackagesCheckedAt":null,"patchAvailable":null,"disclosureDate":"2024-05-18T00:30:42.000Z","capecIds":["CAPEC-242"],"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality","integrity"],"aiComponentTargeted":"api","llmSpecific":false,"classifierConfidence":0.95,"researchCategory":null,"atlasIds":null}}