PYSEC-2026-1542
litellm passes untrusted data to `eval` function without sanitization
Details
A remote code execution (RCE) vulnerability exists in the berriai/litellm project due to improper control of the generation of code when using the `eval` function unsafely in the `litellm.get_secret()` method. Specifically, when the server utilizes Google KMS, untrusted data is passed to the `eval` function without any sanitization. Attackers can exploit this vulnerability by injecting malicious values into environment variables through the `/config/update` endpoint, which allows for the update of settings in `proxy_server_config.yaml`.
Are you affected?
Enter the version of the package you're using.
Affected packages
0No fixed version published yet for litellm (pip). Pin to a known-safe version or switch to an alternative.
References
- https://nvd.nist.gov/vuln/detail/CVE-2024-4264[ADVISORY]
- https://github.com/BerriAI/litellm[PACKAGE]
- https://github.com/BerriAI/litellm/blob/main/litellm/proxy/proxy_server.py#L2104-L2108[WEB]
- https://github.com/BerriAI/litellm/blob/main/litellm/proxy/proxy_server.py#L2118[WEB]
- https://github.com/BerriAI/litellm/blob/main/litellm/proxy/proxy_server.py#L2509-L2517[WEB]
- https://github.com/BerriAI/litellm/blob/main/litellm/proxy/proxy_server.py#L2562-L2577[WEB]
- https://github.com/BerriAI/litellm/blob/main/litellm/utils.py#L9867-L9885[WEB]
- https://huntr.com/bounties/a3221b0c-6e25-4295-ab0f-042997e8fc61[WEB]
- https://pypi.org/project/litellm[PACKAGE]
- https://github.com/advisories/GHSA-7ggm-4rjg-594w[ADVISORY]