Skip to content
LiteLLMGHSA-3xr8-qfvj-9p9j

Arbitrary file deletion in litellm

High6.5CVE-2024-4888 · Published Jun 6, 2024 · updated Sep 10, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
litellm
PyPI
< 1.35.361.35.36
Details and references

BerriAI's litellm, in its latest version, is vulnerable to arbitrary file deletion due to improper input validation on the `/audio/transcriptions` endpoint. An attacker can exploit this vulnerability by sending a specially crafted request that includes a file path to the server, which then deletes the specified file without proper authorization or validation. This vulnerability is present in the code where `os.remove(file.filename)` is used to delete a file, allowing any user to delete critical files on the server such as SSH keys, SQLite databases, or configuration files.

CVSS 3.0
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-20, CWE-862
Also known as
CVE-2024-4888, PYSEC-2026-1540

More LiteLLM advisories

All LiteLLM
DateAdvisory
Jun 62024SQL injection in litellm
CVE-2024-4890Medium4.9no fix yet
Jun 62024SQL injection in litellm
CVE-2024-5225Medium6.4fixed in 1.40.0
May 182024litellm passes untrusted data to `eval` function without sanitization
CVE-2024-4264High7.2no fix yet
Jun 272024litellm vulnerable to remote code execution based on using eval unsafely
CVE-2024-5751Critical9.8fixed in 1.40.16
Jun 272024litellm vulnerable to improper access control in team management
CVE-2024-5710Medium5.3fixed in 1.40.15
Apr 102024LiteLLM has Server-Side Template Injection vulnerability in /completions endpoint
CVE-2024-2952Critical9.8fixed in 1.34.42

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.