{"id":"CVE-2024-4890","aliases":["GHSA-8j42-pcfm-3467","PYSEC-2026-1544"],"url":"https://o3.security/vulnerability/CVE-2024-4890","summary":"Blind SQL Injection in berriai/litellm","details":"A blind SQL injection vulnerability exists in the berriai/litellm application, specifically within the '/team/update' process. The vulnerability arises due to the improper handling of the 'user_id' parameter in the raw SQL query used for deleting users. An attacker can exploit this vulnerability by injecting malicious SQL commands through the 'user_id' parameter, leading to potential unauthorized access to sensitive information such as API keys, user information, and tokens stored in the database. The affected version is 1.27.14.","published":"2024-06-06T18:23:49.593Z","modified":"2026-08-12T03:51:38.133230842Z","cvss":{"score":4.9,"severity":"MEDIUM","vector":"CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N"},"epss":{"score":0.0056,"percentile":0.45231,"asOf":"2026-09-17"},"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"PyPI","name":"litellm","fixedVersion":null}],"fix":{"url":"https://github.com/BerriAI/litellm/pull/2954","label":"BerriAI/litellm#2954"},"references":[{"type":"WEB","url":"https://huntr.com/bounties/a4f6d357-5b44-4e00-9cac-f1cc351211d2"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/4xxx/CVE-2024-4890.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-4890"},{"type":"WEB","url":"https://github.com/BerriAI/litellm/pull/2954"},{"type":"PACKAGE","url":"https://github.com/BerriAI/litellm"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:38.133230842Z"}}