Critical severity9.8NVD Advisory· Published Jun 27, 2024· Updated Jun 17, 2026
CVE-2024-5751
CVE-2024-5751
Description
BerriAI/litellm version v1.35.8 contains a vulnerability where an attacker can achieve remote code execution. The vulnerability exists in the add_deployment function, which decodes and decrypts environment variables from base64 and assigns them to os.environ. An attacker can exploit this by sending a malicious payload to the /config/update endpoint, which is then processed and executed by the server when the get_secret function is triggered. This requires the server to use Google KMS and a database to store a model.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
litellmPyPI | < 1.40.16 | 1.40.16 |
Affected products
3- berriai/berriai/litellmv5Range: unspecified
Patches
Vulnerability mechanics
References
5- github.com/advisories/GHSA-gppg-gqw8-wh9gghsaADVISORY
- huntr.com/bounties/ae623c2f-b64b-4245-9ed4-f13a0a5824cenvdThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2024-5751ghsaADVISORY
- github.com/BerriAI/litellm/commit/fcea4c22ad96b24436f196ae709f71932e84b0b8ghsaWEB
- github.com/BerriAI/litellm/pull/4228ghsaWEB
News mentions
0No linked articles in our index yet.