litellm is vulnerable to Improper Input Validation
80
High Risk
Affected versions of the package are vulnerable to improper input validation. Users can specify the api_base parameter when making requests to POST /chat/completions. The application then sends the request to the domain specified by api_base, which includes the OpenAI API key. A malicious user can set api_base to their own domain and invoke POST /chat/completions to intercept and steal the OpenAI API key.
You are affected if you are using a version that falls within the vulnerable range.
litellm is vulnerable to Improper Input Validation in versions 1.40.15 - 1.44.8.
Upgrade the litellm library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant