Skip to content
MediumVulnerabilityLLM-specific

GHSA-h6m6-jj8v-94jj: SQL injection in litellm

Published
Record updated
View JSON
Affected
  • litellm < 1.40.0
Fixed in
1.40.0
Known exploitation
Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
EPSS
0.4%

Summary

An SQL injection flaw exists in the berriai/litellm repository, in the `/global/spend/logs` endpoint. The affected code builds an SQL query by concatenating an unvalidated `api_key` parameter directly into it, so malicious data in that parameter can alter the query. The source says it affects the latest version of the repository and that exploitation could lead to unauthorized access, data manipulation, exposure of confidential information, and denial of service.

Mitigation

The source does not state a fix yet. Check the original advisory for updates.