Skip to content
CriticalVulnerabilityLLM-specific

GHSA-gppg-gqw8-wh9g: litellm vulnerable to remote code execution based on using eval unsafely

Published
Record updated
View JSON
Affected
  • litellm < 1.40.16
Fixed in
1.40.16
Known exploitation
Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
EPSS
0.9%

Summary

BerriAI/litellm version v1.35.8 contains a flaw that allows remote code execution. The `add_deployment` function decodes and decrypts base64 environment variables and assigns them to `os.environ`, and an attacker can send a malicious payload to the `/config/update` endpoint, which the server processes and executes when `get_secret` is triggered. Exploitation requires the server to use Google KMS and a database to store a model.

Mitigation

The source does not state a fix yet. Check the original advisory for updates.