CodexGuild Knowledge Base
LiteLLM has Server-Side Template Injection vulnerability in /completions endpoint
Canonical as of Apr 10, 2024
LiteLLM has Server-Side Template Injection vulnerability in /completions endpoint
Critical severity. Affects litellm < 1.34.42. Upgrade to 1.34.42 or later.
CVE-2024-2952 / GHSA-46cm-pfwv-cgf8 · severity: critical · CVSS 9.8 · PyPI
Affected
litellm< 1.34.42 → fixed in 1.34.42
Details
BerriAI/litellm is vulnerable to Server-Side Template Injection (SSTI) via the /completions endpoint. The vulnerability arises from the hf_chat_template method processing the chat_template parameter from the tokenizer_config.json file through the Jinja template engine without proper sanitization. Attackers can exploit this by crafting malicious tokenizer_config.json files that execute arbitrary code on the server.
Source: GHSA-46cm-pfwv-cgf8 — GitHub Advisory Database (CC-BY-4.0).