Skip to content
LowVulnerabilityLLM-specific

GHSA-p897-vf7j-f5h8: BerriAI litellm has Security Feature Bypass in BannedKeywords and AzureContentSafety Guardrails via call_type Mismatch on Async Endpoints

Published
Record updated
View JSON
Affected
  • litellm <= 1.82.5
Fixed in
No fixed version was stated when the source was last read.
Known exploitation
Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
EPSS
0.4%

Summary

A flaw in BerriAI litellm up to 1.82.5 affects the async_pre_call_hook function in enterprise/enterprise_hooks/banned_keywords.py, part of the Completions Interface. Manipulating the prompt argument results in incorrect authorization, and the attack can be carried out remotely. A public exploit has been released, and the vendor was contacted early about the disclosure.

Mitigation

The source does not state a fix yet. Check the original advisory for updates.