漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
LiteLLM: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Vulnerability Description
LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.7-stable, LiteLLM Skills archive extraction did not sufficiently validate file paths from uploaded skill ZIP archives, allowing an authenticated user with access to LiteLLM LLM API routes or a key whose allowed_routes includes /v1/skills, anthropic_routes, or llm_api_routes to upload a crafted skill archive containing path traversal entries that could be written outside the intended extraction or staging directory. This issue is fixed in version 1.83.7-stable.
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N
Vulnerability Type
对路径名的限制不恰当(路径遍历)
Vulnerability Title
LiteLLM 路径遍历漏洞
Vulnerability Description
LiteLLM是LiteLLM团队开源的一个应用程序。 LiteLLM 1.83.7-stable之前版本存在路径遍历漏洞,该漏洞源于对上传的技能ZIP存档中文件路径验证不充分,可能导致经过身份验证的用户上传包含路径遍历条目的特制技能存档,从而将文件写入预期提取或暂存目录之外。
CVSS Information
N/A
Vulnerability Type
N/A