Feed/CVE-2024-2952
CVE-2024-2952CRITICALCVSS 9.8

LiteLLM has Server-Side Template Injection vulnerability in /completions endpoint

Published Apr 10, 2024·Updated Jul 6, 2026

NVD Description

BerriAI/litellm is vulnerable to Server-Side Template Injection (SSTI) via the `/completions` endpoint. The vulnerability arises from the `hf_chat_template` method processing the `chat_template` parameter from the `tokenizer_config.json` file through the Jinja template engine without proper sanitization. Attackers can exploit this by crafting malicious `tokenizer_config.json` files that execute arbitrary code on the server.

Affected Packages (1)

litellmPYPI
Fixed in 1.34.42

CVSS Vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free