CVE-2024-4889: Code Injection in berriai/litellm

Published Jun 6, 2024
·
Updated

A code injection vulnerability exists in the berriai/litellm application, version 1.34.6, due to the use of unvalidated input in the eval function within the secret management system. This vulnerability requires a valid Google KMS configuration file to be exploitable. Specifically, by setting the UILOGOPATH variable to a remote server address in the getimage function, an attacker can write a malicious Google KMS configuration file to the cachedlogo.jpg file. This file can then be used to execute arbitrary code by assigning malicious code to the SAVECONFIGTODB environment variable, leading to full system control. The vulnerability is contingent upon the use of the Google KMS feature.

Affected Software

1 affected component
LiteLLM LiteLLM<1.44.16

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade berriai/litellm to a version that resolves this vulnerability.

    Fixed in 1.34.6
  2. Configuration

    Do not set UI_LOGO_PATH to a remote server address; ensure it cannot point to attacker-controlled remote content in the get_image function.

    berriai/litellm secret management system (get_image) UI_LOGO_PATH = Unset or set to a local/verified path only (no remote server address)
  3. Configuration

    Disable the Google KMS feature when not needed, since exploitation is contingent upon using the Google KMS feature and requires a valid Google KMS configuration file.

    berriai/litellm secret management system Google KMS feature = Disable if not required
  4. Configuration

    Prevent attackers from influencing SAVE_CONFIG_TO_DB, since malicious assignment can lead to arbitrary code execution and full system control after the malicious cached_logo.jpg is created.

    berriai/litellm secret management system SAVE_CONFIG_TO_DB = Ensure unset/disabled and only set via trusted, validated configuration

Event History

Jun 6, 2024
CVE Published
via MITRE·05:53 PM
Data Sourced
via MITRE·05:53 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2024-4889?

CVE-2024-4889 has a high severity rating due to its potential for code injection attacks.

2

How do I fix CVE-2024-4889?

To fix CVE-2024-4889, ensure that all user inputs are validated before being processed by the eval function.

3

What is the affected version for CVE-2024-4889?

CVE-2024-4889 affects the berriai/litellm application version 1.34.6 up to, but not including, version 1.44.16.

4

What type of vulnerability is CVE-2024-4889?

CVE-2024-4889 is a code injection vulnerability resulting from the use of unvalidated input.

5

Is a specific configuration needed to exploit CVE-2024-4889?

Yes, a valid Google KMS configuration file is required to exploit CVE-2024-4889.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203