CodexGuild Knowledge Base
LiteLLM Server-Side Request Forgery (SSRF) vulnerability
Canonical as of Sep 13, 2024
LiteLLM Server-Side Request Forgery (SSRF) vulnerability
High severity. Affects litellm < 1.44.8. Upgrade to 1.44.8 or later.
CVE-2024-6587 / GHSA-g26j-5385-hhw3 · severity: high · CVSS 7.5 · PyPI
Affected
litellm< 1.44.8 → fixed in 1.44.8
Details
A Server-Side Request Forgery (SSRF) vulnerability exists in berriai/litellm version 1.38.10. This vulnerability allows users to specify the api_base parameter when making requests to POST /chat/completions, causing the application to send the request to the domain specified by api_base. This request includes the OpenAI API key. A malicious user can set the api_base to their own domain and intercept the OpenAI API key, leading to unauthorized access and potential misuse of the API key.
Source: GHSA-g26j-5385-hhw3 — GitHub Advisory Database (CC-BY-4.0).