GHSA-3cv6-jpf6-8222: SSRF
Impact
Any authenticated LiteLLM proxy user could redirect an outbound provider call to a destination they control and cause the proxy to send its own configured provider credentials to that destination. The proxy's request-body validation was a denylist that did not cover every sensitive parameter and did not inspect parameters nested inside other request fields, so a caller could supply a routing or credential value that the proxy applied without clearing the operator's stored key. Any authenticated user could therefore exfiltrate the operator's upstream provider credentials and other configured secrets, and perform Server-Side Request Forgery against internal services reachable from the proxy.
Patches
Fixed in 1.96.2, 1.95.1, 1.94.3, 1.93.2, 1.92.2, 1.91.5, 1.90.7, 1.89.7, and 1.88.6.
Workarounds
Set generalsettings.allowclientsidecredentials to false so callers cannot override connection parameters, restrict proxy keys to trusted callers, and block the affected parameters (apibase, baseurl, modellist, fallbacks, provider credential fields) at a reverse proxy or API gateway.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
pip/litellmto a version that resolves this vulnerability.Fixed in 1.96.2 - Upgrade
Upgrade
pip/litellmto a version that resolves this vulnerability.Fixed in 1.95.1 - Upgrade
Upgrade
pip/litellmto a version that resolves this vulnerability.Fixed in 1.94.3 - Upgrade
Upgrade
pip/litellmto a version that resolves this vulnerability.Fixed in 1.93.2 - Upgrade
Upgrade
pip/litellmto a version that resolves this vulnerability.Fixed in 1.92.2 - Upgrade
Upgrade
pip/litellmto a version that resolves this vulnerability.Fixed in 1.91.5 - Upgrade
Upgrade
pip/litellmto a version that resolves this vulnerability.Fixed in 1.90.7 - Upgrade
Upgrade
pip/litellmto a version that resolves this vulnerability.Fixed in 1.89.7 - Upgrade
Upgrade
pip/litellmto a version that resolves this vulnerability.Fixed in 1.88.6 - Upgrade
Upgrade
LiteLLM proxyto a version that resolves this vulnerability.Fixed in 1.96.2 - Upgrade
Upgrade
LiteLLM proxyto a version that resolves this vulnerability.Fixed in 1.95.1 - Upgrade
Upgrade
LiteLLM proxyto a version that resolves this vulnerability.Fixed in 1.94.3 - Upgrade
Upgrade
LiteLLM proxyto a version that resolves this vulnerability.Fixed in 1.93.2 - Upgrade
Upgrade
LiteLLM proxyto a version that resolves this vulnerability.Fixed in 1.92.2 - Upgrade
Upgrade
LiteLLM proxyto a version that resolves this vulnerability.Fixed in 1.91.5 - Upgrade
Upgrade
LiteLLM proxyto a version that resolves this vulnerability.Fixed in 1.90.7 - Upgrade
Upgrade
LiteLLM proxyto a version that resolves this vulnerability.Fixed in 1.89.7 - Upgrade
Upgrade
LiteLLM proxyto a version that resolves this vulnerability.Fixed in 1.88.6 - Configuration
Set general_settings.allow_client_side_credentials to false so callers cannot override connection parameters.
LiteLLM proxy general_settings.allow_client_side_credentials = false - Compensating control
Restrict proxy keys to trusted callers, and block api_base, base_url, model_list, fallbacks, and provider credential fields at a reverse proxy or API gateway.
Event History
Frequently Asked Questions
Who can exploit this issue?
Any authenticated LiteLLM proxy user can exploit it. The affected proxy must have configured upstream provider credentials or other secrets that the attacker can cause it to use or expose.
What could an attacker do after exploiting it?
An authenticated caller can redirect an outbound provider request to an attacker-controlled destination, causing the proxy to send its configured provider credentials there. They can also use the proxy for SSRF against internal services reachable from the proxy.
Are default request validation controls sufficient?
No. The vulnerable validation used a denylist that did not cover all sensitive parameters and did not inspect sensitive values nested in other request fields.
What can be done if upgrading is not immediately possible?
Set general_settings.allow_client_side_credentials to false, limit proxy keys to trusted callers, and block api_base, base_url, model_list, fallbacks, and provider credential fields at a reverse proxy or API gateway.
Which LiteLLM versions contain fixes?
Fixed versions are 1.96.2, 1.95.1, 1.94.3, 1.93.2, 1.92.2, 1.91.5, 1.90.7, 1.89.7, and 1.88.6.