HighVulnerabilityLLM-specific
GHSA-53gh-p8jc-7rg8: LiteLLM Vulnerable to Remote Code Execution (RCE)
- Identifiers
- CVE-2024-6825GHSA-53gh-p8jc-7rg8
- Published
- Record updated
- Affected
- litellm >= 1.40.3.dev2, <= 1.40.12
- Fixed in
- No fixed version was stated when the source was last read.
- Known exploitation
- Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
- EPSS
- 1.7%
Summary
BerriAI/litellm version 1.40.12 contains a remote code execution flaw in how it handles the 'post_call_rules' configuration. The configured callback value is split at its final '.', and the last part is treated as the function name while the remainder is appended with '.py' and imported, so an attacker can set a system method such as 'os.system' as a callback and run arbitrary commands when a chat response is processed.
Mitigation
The source does not state a fix yet. Check the original advisory for updates.
Affected packages in the Exposure Registry
Matched by package name and ecosystem. Each entry shows whether the package delegates to a language model and how many tracked packages depend on it.
- litellmPyPILLM dependency since 2023-07-27 · 54 tracked dependents
Related items
- LowAnthropic Cuts Live Internet Access for Internal AI Tests After Claude Exploits Injection FlawsSimilar attack · The Hacker News
- CriticalCVE-2026-108263: Astron Agent code-node execution as root through workflow run endpointsSimilar attack · NVD/CVE Database
- MediumHackers abuse Google Ads, Bing redirects to push Claude ClickFix attacksSimilar attack · BleepingComputer
- CriticalHermes Agent - PKCE Session Takeover via Redirect-URI Parser ConfusionSimilar attack · Tenable Research Advisories
- LowSocial Engineering AI Agents: The New BEC for 2026Similar attack · Dark Reading