Horizon Alert
Summary of the vulnerability and why it matters
A critical security vulnerability has been identified in the litellm software, specifically affecting its handling of server-side template injection. This flaw could allow remote attackers to execute unauthorized commands on the underlying operating system without needing any credentials, posing a significant risk to systems utilizing this technology.
- Unauthenticated remote attackers can run commands.
- Critical issue in templating, impacting command execution.
- Confirm relevance and assess exposure to this risk.
Attack Path
How an attacker could exploit the issue
An attacker can exploit this vulnerability by sending a specially crafted request to the `/prompts/test` endpoint without needing to authenticate. This request would target the `dotprompt_content` parameter, which is processed using an unsandboxed templating engine. Successful exploitation could allow the attacker to execute arbitrary operating system commands on the server.
- Unauthenticated access to the `/prompts/test` endpoint.
- Crafted `dotprompt_content` parameter in a request.
- Remote command execution on the server.
Live Threat
Current exploitation, exposure, and threat context
This vulnerability could allow unauthenticated attackers to execute arbitrary operating system commands. This may occur when the `/prompts/test` endpoint is accessed with a specially crafted `dotprompt_content` parameter, bypassing intended security measures due to the use of an unsandboxed Jinja2 environment.
- OS command execution.
- Via crafted `dotprompt_content` parameter.
- Compromise of the server.
Operational Fix
Recommended remediation, mitigation, and detection steps
The litellm proxy, particularly the `/prompts/test` endpoint, is likely managed by platform or application teams responsible for LLM services. The first step is to identify all instances of litellm, determine their network exposure and business criticality, and then locate the accountable owner for remediation planning.
- Platform or application teams own this.
- Verify litellm instances and exposure.
- Plan remediation based on identified risk.