CRITICAL 9.8 PyPI

LiteLLM has Server-Side Template Injection vulnerability in /completions endpoint

GHSA-46cm-pfwv-cgf8 · CVE-2024-2952 · PYSEC-2026-387

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

BerriAI/litellm is vulnerable to Server-Side Template Injection (SSTI) via the /completions endpoint. The vulnerability arises from the hf_chat_template method processing the chat_template parameter from the tokenizer_config.json file through the Jinja template engine without proper sanitization. Attackers can exploit this by crafting malicious tokenizer_config.json files that execute arbitrary code on the server.

Ready to move

Start Securing

Free, no credit card | First findings in minutes