litellm is vulnerable to Improper Input Validation
80
High Risk
Affected versions of the package are vulnerable to improper input validation. Users can specify the api_base parameter when making requests to POST /chat/completions. The application then sends the request to the domain specified by api_base, which includes the OpenAI API key. A malicious user can set api_base to their own domain and invoke POST /chat/completions to intercept and steal the OpenAI API key.
You are affected if you are using a version that falls within the vulnerable range.
litellm is vulnerable to Improper Input Validation in versions 1.40.15 - 1.44.8.
Upgrade the litellm library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant