Impact
LiteLLM, an AI‑Gateway proxy, allows an authenticated caller with a valid virtual key to embed an arbitrary api_base URL within the user_config payload. By bypassing the is_request_body_safe check, the proxy constructs outbound routing that can direct traffic to any internal or external host chosen by the attacker. This enables server‑side request forgery, allowing the proxy server to reach endpoints otherwise inaccessible, potentially leaking sensitive data or facilitating further internal compromise. The flaw is a CWE‑918 issue involving improper validation of input data.
Affected Systems
The vulnerability appears in the LiteLLM product from BerriAI. Versions earlier than 1.83.9 are impacted, including 1.83.8 and earlier. No other products or vendor versions are identified as affected.
Risk and Exploitability
The CVSS score of 5.3 denotes moderate severity. The EPSS score indicates a very low current probability of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. Based on the description, the attack vector is inferred to be limited to authenticated users possessing a valid virtual key, so the vector requires legitimate credential usage or credential compromise. The exploit path requires modifying the user_config data to redirect outbound calls, and although the risk is moderate, remediation is recommended to prevent internal data exposure or further compromise.
OpenCVE Enrichment
Github GHSA