CVE-2024-6587 is a Server-Side Request Forgery (SSRF) vulnerability in berriai/litellm version 1.38.10. It allows an attacker to specify an arbitrary domain via the api_base parameter in POST /chat/completions requests, causing the application to forward the request, including the OpenAI API key, to the attacker's controlled server. This vulnerability is rated High severity (CVSS 7.5) due to its network attack vector, low complexity, and high confidentiality impact, enabling unauthorized access and potential misuse of the intercepted API key. While not currently listed in KEV or Hot Lists, a Nuclei template for exploitation exists, and despite its high EPSS score, there is no observed active exploitation or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.38.10CPE matchmatch criteria | cpe:2.3:a:litellm:litellm:1.38.10:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.