Skip to content
MediumVulnerabilityLLM-specific

GHSA-8j42-pcfm-3467: SQL injection in litellm

Published
Record updated
View JSON
Affected
  • litellm <= 1.27.14
Fixed in
No fixed version was stated when the source was last read.
Known exploitation
Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
EPSS
0.6%

Summary

A blind SQL injection vulnerability in the berriai/litellm application affects the '/team/update' process. The flaw stems from improper handling of the 'user_id' parameter in a raw SQL query used to delete users, letting an attacker inject SQL through that parameter. The affected version is 1.27.14.

Mitigation

The source does not state a fix yet. Check the original advisory for updates.