Knowledge base
CodexGuild Knowledge Base

LiteLLM has Server-Side Template Injection vulnerability in /completions endpoint

as of Apr 10, 2024 · applies to litellm < 1.34.42 · canonical · codexguild.com/kb/ghsa-46cm-pfwv-cgf8 · exported 2026-10-11
Canonical as of Apr 10, 2024

LiteLLM has Server-Side Template Injection vulnerability in /completions endpoint

Critical severity. Affects litellm < 1.34.42. Upgrade to 1.34.42 or later.

CVE-2024-2952 / GHSA-46cm-pfwv-cgf8 · severity: critical · CVSS 9.8 · PyPI

Affected

  • litellm < 1.34.42 → fixed in 1.34.42

Details

BerriAI/litellm is vulnerable to Server-Side Template Injection (SSTI) via the /completions endpoint. The vulnerability arises from the hf_chat_template method processing the chat_template parameter from the tokenizer_config.json file through the Jinja template engine without proper sanitization. Attackers can exploit this by crafting malicious tokenizer_config.json files that execute arbitrary code on the server.

Source: GHSA-46cm-pfwv-cgf8 — GitHub Advisory Database (CC-BY-4.0).