Site icon Version 2 Limited

Security Bulletin: LiteLLM RCE Chain


Critical Threat Alert: LiteLLM Proxy RCE Chain

Multiple vulnerabilities (SQLi, SSTI, and Command Injection) have been disclosed, allowing for full system compromise of LiteLLM instances.

Vulnerability Summary

Advisory IDTypeAccess LevelSeverity
GHSA-r75f-5x8p-qvmcSQL InjectionUnauthenticatedCritical (9.3)
GHSA-xqmj-j6mv-4862SSTIAuthenticatedHigh
GHSA-v4p8-mg3p-g94gCommand ExecutionAuthenticatedHigh

Remediation Guidance

Affected Versions: v1.81.16 – v1.83.6

Recommended Action: Immediately upgrade to v1.83.7-stable or later.

Network Hunting (runZero Query)

Identify exposed LiteLLM instances by searching for specific HTTP headers and HTML titles:

_asset.protocol:http AND protocol:http AND (html.title:=”LiteLLM%” OR last.html.title:=”LiteLLM%”)
Exit mobile version