Intel

AIKIDO-2024-10128

litellm is vulnerable to Information Disclosure

Information Disclosure Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Jun 13, 2024

40

Medium Risk

This Affects:

pythonlitellm
0.1.0 - 1.40.5
Fixed in 1.40.6
Are you affected? Scan for Free

TL;DR

Affected versions of litellm include the raw request in the metadata of spend logs, which may include authorization and other sensitive headers.

Who does this affect?

You are affected if you use a vulnerable version of litellm.

Background info

litellm is vulnerable to Information Disclosure in versions 0.1.0 - 1.40.5.

How to fix this

Upgrade litellm to a patch version.