{"data":{"id":"b68fe5d3-c418-43a8-ad55-e80988888949","title":"GHSA-h6m6-jj8v-94jj: SQL injection in litellm","summary":"An SQL injection flaw exists in the berriai/litellm repository, in the `/global/spend/logs` endpoint. The affected code builds an SQL query by concatenating an unvalidated `api_key` parameter directly into it, so malicious data in that parameter can alter the query. The source says it affects the latest version of the repository and that exploitation could lead to unauthorized access, data manipulation, exposure of confidential information, and denial of service.","solution":"N/A -- no mitigation discussed in source.","labels":["security"],"sourceUrl":"https://github.com/advisories/GHSA-h6m6-jj8v-94jj","publishedAt":"2024-06-06T21:30:37.000Z","cveId":"CVE-2024-5225","cweIds":["CWE-89"],"cvssScore":"6.4","cvssSeverity":"medium","severity":"medium","attackType":["other"],"issueType":"vulnerability","affectedPackages":["litellm@< 1.40.0 (fixed: 1.40.0)"],"affectedPackageNames":["litellm"],"affectedPackageRefs":["pypi:litellm"],"affectedVendors":[],"affectedVendorsRaw":["LiteLLM"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","summaryPromptVersion":"v2","headline":null,"headlinePromptVersion":null,"cvssVector":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N","attackVector":"network","attackComplexity":"low","privilegesRequired":"low","userInteraction":"none","exploitMaturity":"unknown","epssScore":0.00429,"epssCheckedAt":"2026-10-10T04:57:09.144Z","kevDateAdded":null,"advisoryAliases":["GHSA-h6m6-jj8v-94jj"],"affectedPackagesSource":null,"affectedPackagesCheckedAt":null,"patchAvailable":true,"disclosureDate":"2024-06-06T21:30:37.000Z","capecIds":["CAPEC-66"],"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality","integrity","availability"],"aiComponentTargeted":"api","llmSpecific":true,"classifierConfidence":0.9,"researchCategory":null,"atlasIds":null}}