Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. Heads up: LiteLLM, a very popular AI model wrapper, has been compromised.

Heads up: LiteLLM, a very popular AI model wrapper, has been compromised.

Scheduled Pinned Locked Moved Uncategorized
5 Posts 3 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • mttaggart@infosec.exchangeM This user is from outside of this forum
    mttaggart@infosec.exchangeM This user is from outside of this forum
    mttaggart@infosec.exchange
    wrote last edited by
    #1

    Heads up: LiteLLM, a very popular AI model wrapper, has been compromised. See the attached issue for details and recommended actions.

    https://github.com/BerriAI/litellm/issues/24518

    mttaggart@infosec.exchangeM 1 Reply Last reply
    1
    0
    • R relay@relay.infosec.exchange shared this topic
    • mttaggart@infosec.exchangeM mttaggart@infosec.exchange

      Heads up: LiteLLM, a very popular AI model wrapper, has been compromised. See the attached issue for details and recommended actions.

      https://github.com/BerriAI/litellm/issues/24518

      mttaggart@infosec.exchangeM This user is from outside of this forum
      mttaggart@infosec.exchangeM This user is from outside of this forum
      mttaggart@infosec.exchange
      wrote last edited by
      #2

      No kidding, this package is in a lot more places than you might expect. PyPi has removed the package, but versions 1.82.7 and 1.82.8 are affected. Search for them in your environment now.

      varx@defcon.socialV 1 Reply Last reply
      1
      0
      • mttaggart@infosec.exchangeM mttaggart@infosec.exchange

        No kidding, this package is in a lot more places than you might expect. PyPi has removed the package, but versions 1.82.7 and 1.82.8 are affected. Search for them in your environment now.

        varx@defcon.socialV This user is from outside of this forum
        varx@defcon.socialV This user is from outside of this forum
        varx@defcon.social
        wrote last edited by
        #3

        @mttaggart when you check your cluster and the container was on 1.82.6 . that was a close one.

        richardoc@infosec.exchangeR 1 Reply Last reply
        0
        • varx@defcon.socialV varx@defcon.social

          @mttaggart when you check your cluster and the container was on 1.82.6 . that was a close one.

          richardoc@infosec.exchangeR This user is from outside of this forum
          richardoc@infosec.exchangeR This user is from outside of this forum
          richardoc@infosec.exchange
          wrote last edited by
          #4

          @varx @mttaggart official containers are thought to be unaffected (as of 16:03UTC )

          mttaggart@infosec.exchangeM 1 Reply Last reply
          0
          • richardoc@infosec.exchangeR richardoc@infosec.exchange

            @varx @mttaggart official containers are thought to be unaffected (as of 16:03UTC )

            mttaggart@infosec.exchangeM This user is from outside of this forum
            mttaggart@infosec.exchangeM This user is from outside of this forum
            mttaggart@infosec.exchange
            wrote last edited by
            #5

            @RichardoC @varx Yes, based on pinning to earlier versions, per this comment:

            https://github.com/BerriAI/litellm/issues/24518#issuecomment-4119145829

            1 Reply Last reply
            0
            Reply
            • Reply as topic
            Log in to reply
            • Oldest to Newest
            • Newest to Oldest
            • Most Votes


            • Login

            • Login or register to search.
            • First post
              Last post
            0
            • Categories
            • Recent
            • Tags
            • Popular
            • World
            • Users
            • Groups