Database/AI/ML frameworks & serving

LiteLLM: Arbitrary file deletion via `/audio/transcriptions`
CVSS 8.1CVE-2024-4888AI/ML frameworks & servingcurated
Impact
Arbitrary file deletion via /audio/transcriptions
Who can reach it
Network user of the proxy
What to do
Upgrade
References
Related entries
- LiteLLM: Unauthenticated DoS via `ast.literal_eval` on user inputCVE-2024-10188 · LiteLLMHigh
- MLflow (REST API): DNS rebinding — no Origin header validationCVE-2025-14279 · MLflow (REST API)High
- NVIDIA Triton (Python backend): Out-of-bounds write in the Python backendCVE-2025-23318 · NVIDIA Triton (Python backend)High
- NVIDIA Triton (Python backend shared memory): Out-of-bounds write in the Python backendCVE-2025-23319 · NVIDIA Triton (Python backend shared memory)High
- LibreChat: agent Actions have no destination restrictions by default, reaching internal services via SSRFCVE-2025-69222 · LibreChat (agent Actions feature, outbound request allowlist)High
- picklescan: Misses `idlelib.pyshell.ModifiedInterpreter.runcode` gadgetCVE-2025-71340 · picklescanHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.