Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-6825

Опубликовано: 20 мар. 2025
Источник: nvd
CVSS3: 8.8
EPSS Низкий

Описание

BerriAI/litellm version 1.40.12 contains a vulnerability that allows remote code execution. The issue exists in the handling of the 'post_call_rules' configuration, where a callback function can be added. The provided value is split at the final '.' mark, with the last part considered the function name and the remaining part appended with the '.py' extension and imported. This allows an attacker to set a system method, such as 'os.system', as a callback, enabling the execution of arbitrary commands when a chat response is processed.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:litellm:litellm:*:*:*:*:*:*:*:*
Версия до 1.65.4 (исключая)
cpe:2.3:a:litellm:litellm:1.65.4:dev2:*:*:*:*:*:*

EPSS

Процентиль: 80%
0.01349
Низкий

8.8 High

CVSS3

Дефекты

CWE-94

Связанные уязвимости

CVSS3: 8.8
github
11 месяцев назад

LiteLLM Vulnerable to Remote Code Execution (RCE)

EPSS

Процентиль: 80%
0.01349
Низкий

8.8 High

CVSS3

Дефекты

CWE-94