GHSA-46cm-pfwv-cgf8CriticalCVSS 9.8

LiteLLM has Server-Side Template Injection vulnerability in /completions endpoint

Published
April 10, 2024
Last Modified
July 6, 2026

🔗 CVE IDs covered (1)

📋 Description

BerriAI/litellm is vulnerable to Server-Side Template Injection (SSTI) via the /completions endpoint. The vulnerability arises from the hf_chat_template method processing the chat_template parameter from the tokenizer_config.json file through the Jinja template engine without proper sanitization. Attackers can exploit this by crafting malicious tokenizer_config.json files that execute arbitrary code on the server.

🎯 Affected products1

  • pip/litellm:< 1.34.42

🔗 References (10)