Skip to content
HighVulnerabilityLLM-specific

GHSA-53gh-p8jc-7rg8: LiteLLM Vulnerable to Remote Code Execution (RCE)

Published
Record updated
View JSON
Affected
  • litellm >= 1.40.3.dev2, <= 1.40.12
Fixed in
No fixed version was stated when the source was last read.
Known exploitation
Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
EPSS
1.7%

Summary

BerriAI/litellm version 1.40.12 contains a remote code execution flaw in how it handles the 'post_call_rules' configuration. The configured callback value is split at its final '.', and the last part is treated as the function name while the remainder is appended with '.py' and imported, so an attacker can set a system method such as 'os.system' as a callback and run arbitrary commands when a chat response is processed.

Mitigation

The source does not state a fix yet. Check the original advisory for updates.