PyPI package
litellm
pkg:pypi/litellm
Malware
3 malicious versions on record
One or more versions of this package have been flagged as containing malicious code. Audit any system that installed an affected version.
- GHSA-92x9-889m-jgmwMalicious code in litellm (PyPI)Jul 21, 2026
- PYSEC-2026-2Two litellm versions published containing credential harvesting malwareMar 24, 2026
- MAL-2026-2144Malicious code in litellm (PyPI)Mar 24, 2026
Vulnerabilities (21)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2024-2952 | Cri | 9.8 | < 1.34.42 | 1.34.42 | Apr 10, 2024 | BerriAI/litellm is vulnerable to Server-Side Template Injection (SSTI) via the `/completions` endpoint. The vulnerability arises from the `hf_chat_template` method processing the `chat_template` parameter from the `tokenizer_config.json` file through the Jinja template engine wit |
- affected < 1.34.42fixed 1.34.42
BerriAI/litellm is vulnerable to Server-Side Template Injection (SSTI) via the `/completions` endpoint. The vulnerability arises from the `hf_chat_template` method processing the `chat_template` parameter from the `tokenizer_config.json` file through the Jinja template engine wit
Page 2 of 2