Описание
LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.7-stable, LiteLLM Skills archive extraction did not sufficiently validate file paths from uploaded skill ZIP archives, allowing an authenticated user with access to LiteLLM LLM API routes or a key whose allowed_routes includes /v1/skills, anthropic_routes, or llm_api_routes to upload a crafted skill archive containing path traversal entries that could be written outside the intended extraction or staging directory. This issue is fixed in version 1.83.7-stable.
A flaw was found in LiteLLM, a proxy server for Large Language Model (LLM) APIs. An authenticated user, with specific API route access, could upload a specially crafted skill archive. This archive, containing path traversal entries, would allow files to be written outside of the designated extraction directory. This vulnerability could lead to arbitrary file creation or modification, potentially resulting in system compromise.
Отчет
LiteLLM prior to 1.83.7-stable does not sufficiently validate file paths extracted from uploaded Skills ZIP archives, allowing path traversal writes outside the intended extraction directory. Exploitation requires the LiteLLM Proxy Server's Skills API (/v1/skills, anthropic_routes, or llm_api_routes) to be enabled and reachable by an authenticated caller. Fixed in 1.83.7-stable.
Меры по смягчению последствий
Upgrade to LiteLLM 1.83.7-stable or later. Products that use LiteLLM only as a Python SDK (litellm.completion()) rather than running the LiteLLM Proxy Server with the Skills feature enabled are not exposed to this vulnerability, as the vulnerable HTTP upload endpoint does not exist in SDK-only usage.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Exploit Intelligence | exploit-intelligence-tech-preview/vulnerability-analysis-rhel9 | Affected | ||
| Lightspeed Core | lightspeed-core/lightspeed-stack-rhel9 | Not affected | ||
| Red Hat Ansible Automation Platform 2 | ansible-automation-platform-26/lightspeed-chatbot-rhel9 | Not affected | ||
| Red Hat Ansible Automation Platform 2 | ansible-automation-platform-27/lightspeed-chatbot-rhel9 | Not affected | ||
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-llama-stack-core-rhel9 | Not affected | ||
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-mlflow-rhel9 | Not affected | ||
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-trustyai-garak-lls-provider-dsp-rhel9 | Not affected |
Показывать по
Ссылки на источники
Дополнительная информация
Статус:
EPSS
8.1 High
CVSS3
Связанные уязвимости
LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.7-stable, LiteLLM Skills archive extraction did not sufficiently validate file paths from uploaded skill ZIP archives, allowing an authenticated user with access to LiteLLM LLM API routes or a key whose allowed_routes includes /v1/skills, anthropic_routes, or llm_api_routes to upload a crafted skill archive containing path traversal entries that could be written outside the intended extraction or staging directory. This issue is fixed in version 1.83.7-stable.
LiteLLM: Arbitrary file write via path traversal in Skills archive extraction
EPSS
8.1 High
CVSS3