Skip to content
CriticalVulnerabilityLLM-specific

GHSA-46cm-pfwv-cgf8: LiteLLM has Server-Side Template Injection vulnerability in /completions endpoint

Published
Record updated
View JSON
Affected
  • litellm < 1.34.42
Fixed in
1.34.42
Known exploitation
Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
EPSS
1.3%

Summary

BerriAI/litellm is vulnerable to Server-Side Template Injection (SSTI) via the `/completions` endpoint. The `hf_chat_template` method passes the `chat_template` parameter from `tokenizer_config.json` through the Jinja template engine without proper sanitization. Attackers can craft malicious `tokenizer_config.json` files to execute arbitrary code on the server.

Mitigation

The source does not state a fix yet. Check the original advisory for updates.