CVE-2024-6587 is a server-side request forgery vulnerability in berriai/litellm affecting version 1.38.10 and originally associated with the POST /chat/completions endpoint. The flaw arises because the application accepts a user-controlled api_base parameter and uses it as the destination for outbound requests. When processing a crafted request, LiteLLM can be induced to send traffic to an attacker-specified host instead of the intended upstream provider. In the vulnerable flow, the outbound request includes the configured OpenAI API key, allowing an attacker to capture that credential. Subsequent reporting indicates the initial fix in LiteLLM 1.44.8 blocked api_base only when present as a top-level request-body field, while nested api_base values inside litellm_params on other endpoints such as /health/test_connection and /model/new were not covered by that guard.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A previously disclosed LiteLLM-related vulnerability mentioned only as background in connection with attacks on exposed AI infrastructure.
A specific vulnerability referenced in the context of active exploitation attempts against AI infrastructure, explicitly stated to be under active exploitation in the wild.
An SSRF vulnerability in LiteLLM that allows attacker-controlled api_base values to cause outbound requests to attacker infrastructure and exfiltrate secrets such as API keys or access cloud metadata. The original fix in LiteLLM 1.44.8 protected the top-level /chat/completions case, but the content describes a nested api_base bypass affecting admin endpoints until later 1.83.x hardening.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.