{"data":{"id":"a5c7c8e3-e49b-46f1-be12-656a7ab05876","title":"GHSA-53gh-p8jc-7rg8: LiteLLM Vulnerable to Remote Code Execution (RCE)","summary":"BerriAI/litellm version 1.40.12 contains a remote code execution flaw in how it handles the 'post_call_rules' configuration. The configured callback value is split at its final '.', and the last part is treated as the function name while the remainder is appended with '.py' and imported, so an attacker can set a system method such as 'os.system' as a callback and run arbitrary commands when a chat response is processed.","solution":"N/A -- no mitigation discussed in source.","labels":["security"],"sourceUrl":"https://github.com/advisories/GHSA-53gh-p8jc-7rg8","publishedAt":"2025-03-20T12:32:45.000Z","cveId":"CVE-2024-6825","cweIds":["CWE-77","CWE-94"],"cvssScore":"8.8","cvssSeverity":"high","severity":"high","attackType":["other"],"issueType":"vulnerability","affectedPackages":["litellm@>= 1.40.3.dev2, <= 1.40.12"],"affectedPackageNames":["litellm"],"affectedPackageRefs":["pypi:litellm"],"affectedVendors":[],"affectedVendorsRaw":["LiteLLM"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","summaryPromptVersion":"v2","headline":null,"headlinePromptVersion":null,"cvssVector":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"network","attackComplexity":"low","privilegesRequired":"low","userInteraction":"none","exploitMaturity":"unknown","epssScore":0.0165,"epssCheckedAt":"2026-10-10T04:57:10.042Z","kevDateAdded":null,"advisoryAliases":["GHSA-53gh-p8jc-7rg8"],"affectedPackagesSource":null,"affectedPackagesCheckedAt":null,"patchAvailable":null,"disclosureDate":"2025-03-20T12:32:45.000Z","capecIds":["CAPEC-242","CAPEC-88"],"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality","integrity","availability"],"aiComponentTargeted":"api","llmSpecific":true,"classifierConfidence":0.95,"researchCategory":null,"atlasIds":null}}