HighVulnerability
GHSA-7ggm-4rjg-594w: litellm passes untrusted data to `eval` function without sanitization
- Identifiers
- CVE-2024-4264GHSA-7ggm-4rjg-594w
- Published
- Record updated
- Affected
- litellm <= 1.28.11
- Fixed in
- No fixed version was stated when the source was last read.
- Known exploitation
- Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
- EPSS
- 0.9%
Summary
A remote code execution flaw in berriai/litellm stems from unsafe use of the `eval` function in the `litellm.get_secret()` method. When the server uses Google KMS, untrusted data reaches `eval` without sanitization. Attackers can inject malicious values into environment variables through the `/config/update` endpoint, which updates settings in `proxy_server_config.yaml`.
Mitigation
The source does not state a fix yet. Check the original advisory for updates.
Affected packages in the Exposure Registry
Matched by package name and ecosystem. Each entry shows whether the package delegates to a language model and how many tracked packages depend on it.
- litellmPyPILLM dependency since 2023-07-27 · 54 tracked dependents
Related items
- MediumARTEX AI, Claude agents used in cyberattacks on South Korean banksSimilar attack · BleepingComputer
- LowAnthropic Cuts Live Internet Access for Internal AI Tests After Claude Exploits Injection FlawsSimilar attack · The Hacker News
- CriticalCVE-2026-108263: Astron Agent code-node execution as root through workflow run endpointsSimilar attack · NVD/CVE Database
- MediumHackers abuse Google Ads, Bing redirects to push Claude ClickFix attacksSimilar attack · BleepingComputer
- CriticalHermes Agent - PKCE Session Takeover via Redirect-URI Parser ConfusionSimilar attack · Tenable Research Advisories