Skip to content
HighVulnerability

GHSA-7ggm-4rjg-594w: litellm passes untrusted data to `eval` function without sanitization

Published
Record updated
View JSON
Affected
  • litellm <= 1.28.11
Fixed in
No fixed version was stated when the source was last read.
Known exploitation
Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
EPSS
0.9%

Summary

A remote code execution flaw in berriai/litellm stems from unsafe use of the `eval` function in the `litellm.get_secret()` method. When the server uses Google KMS, untrusted data reaches `eval` without sanitization. Attackers can inject malicious values into environment variables through the `/config/update` endpoint, which updates settings in `proxy_server_config.yaml`.

Mitigation

The source does not state a fix yet. Check the original advisory for updates.