-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability stemmed from missing parameter validation in the request processing flow. The common_checks function in auth_checks.py was responsible for security validations but did not include the api_base/base_url check prior to the patch. This allowed attackers to inject malicious API endpoints through the request body. The fix added the is_request_body_safe check within common_checks, confirming it was the missing validation point in the vulnerable code path.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| litellm | pip | < 1.44.8 | 1.44.8 |
Ongoing coverage of React2Shell