CVE-2025-45809: SQL Injection
Published Jul 3, 2025
·Updated
SQL Injection vulnerability in BerriAI LiteLLM before 1.81.0 allows attackers to execute arbitrary commands via the key parameter to the "/key/block" and "/key/unblock" API endpoints.
Affected Software
2 affected components
BerriAI LiteLLM
LiteLLM LiteLLM=1.65.4
Event History
Jul 3, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-45809?
CVE-2025-45809 has been classified as a critical vulnerability due to its SQL injection nature.
2
How do I fix CVE-2025-45809?
To mitigate CVE-2025-45809, update BerriAI litellm to a version that addresses the SQL injection vulnerability.
3
What impacts can CVE-2025-45809 have on my system?
CVE-2025-45809 can lead to unauthorized access to the database, data leakage, or data manipulation.
4
Is CVE-2025-45809 exploitable remotely?
Yes, CVE-2025-45809 can be exploited remotely via the /key/block endpoint.
5
What versions of BerriAI litellm are affected by CVE-2025-45809?
BerriAI litellm version 1.65.4 is specifically affected by CVE-2025-45809.