VYPR

PyPI package

litellm

pkg:pypi/litellm

Malware

3 malicious versions on record

One or more versions of this package have been flagged as containing malicious code. Audit any system that installed an affected version.

Vulnerabilities (21)

  • CVE-2024-2952CriApr 10, 2024
    affected < 1.34.42fixed 1.34.42

    BerriAI/litellm is vulnerable to Server-Side Template Injection (SSTI) via the `/completions` endpoint. The vulnerability arises from the `hf_chat_template` method processing the `chat_template` parameter from the `tokenizer_config.json` file through the Jinja template engine wit

Page 2 of 2