Intel

AIKIDO-2024-10245

litellm is vulnerable to SQL Injection

SQL Injection Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Sep 10, 2024

50

Medium Risk

This Affects:

pythonlitellm
1.44.8 - 1.44.16
Fixed in 1.44.17
Are you affected? Scan for Free

TL;DR

Affected versions of the package are vulnerable to SQL Injection in the /team/update query.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

litellm is vulnerable to SQL Injection in versions 1.44.8 - 1.44.16.

How to fix this

Upgrade the litellm library to the patch version.