LiteLLM Proxy vulnerabilities: How to find impacted assets
ID: f594092a-e066-5640-b317-b41ab9e480d5
STIX ID: report--f594092a-e066-5640-b317-b41ab9e480d5
Feed Name: runZero Blog
Threat Score
LiteLLM disclosed three vulnerabilities in LiteLLM Proxy (GHSA-r75f-5x8p-qvmc, GHSA-xqmj-j6mv-4862, GHSA-v4p8-mg3p-g94g) — a SQL injection in API key verification, a server-side template injection in prompt rendering, and an authenticated command execution in MCP test endpoints — which can be chained to achieve remote code execution on affected hosts (LiteLLM versions 1.81.16 through 1.83.6); users are advised to upgrade to v1.83.7-stable or later.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
