CVE-2024-5225
HIGHlitellm < 1.40.2 - SQL Injection via /global/spend/logs API Key Parameter
Title source: llmDescription
An SQL Injection vulnerability exists in the berriai/litellm repository, specifically within the `/global/spend/logs` endpoint. The vulnerability arises due to improper neutralization of special elements used in an SQL command. The affected code constructs an SQL query by concatenating an unvalidated `api_key` parameter directly into the query, making it susceptible to SQL Injection if the `api_key` contains malicious data. This issue affects the latest version of the repository. Successful exploitation of this vulnerability could lead to unauthorized access, data manipulation, exposure of confidential information, and denial of service (DoS).
References (1)
Core 1
Core References
Exploit, Third Party Advisory
https://huntr.com/bounties/491e4884-0306-4cd4-8fe2-9a19de33bf5c
Scores
CVSS v3
7.2
EPSS
0.0024
EPSS Percentile
47.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
total
Details
CWE
CWE-89
Status
published
Products (2)
litellm/litellm
< 1.40.2
pypi/litellm
0 - 1.40.0PyPI
Published
Jun 06, 2024
Tracked Since
Feb 18, 2026