{"id":"CVE-2024-6587","aliases":["GHSA-g26j-5385-hhw3","PYSEC-2026-1547"],"url":"https://o3.security/vulnerability/CVE-2024-6587","summary":"SSRF in berriai/litellm","details":"A Server-Side Request Forgery (SSRF) vulnerability exists in berriai/litellm version 1.38.10. This vulnerability allows users to specify the `api_base` parameter when making requests to `POST /chat/completions`, causing the application to send the request to the domain specified by `api_base`. This request includes the OpenAI API key. A malicious user can set the `api_base` to their own domain and intercept the OpenAI API key, leading to unauthorized access and potential misuse of the API key.","published":"2024-09-13T15:59:53.557Z","modified":"2026-08-08T03:48:08.701215927Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"PyPI","name":"litellm","fixedVersion":"1.44.8"}],"fix":{"url":"https://github.com/berriai/litellm/commit/ba1912afd1b19e38d3704bb156adf887f91ae1e0","label":"berriai/litellm@ba1912a"},"references":[{"type":"WEB","url":"https://huntr.com/bounties/4001e1a2-7b7a-4776-a3ae-e6692ec3d997"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/6xxx/CVE-2024-6587.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-6587"},{"type":"FIX","url":"https://github.com/berriai/litellm/commit/ba1912afd1b19e38d3704bb156adf887f91ae1e0"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-08T03:48:08.701215927Z"}}