{"id":"CVE-2025-45809","details":"SQL Injection vulnerability in BerriAI LiteLLM before 1.81.0 allows attackers to execute arbitrary commands via the key parameter to the \"/key/block\" and \"/key/unblock\" API endpoints.","modified":"2026-08-12T03:51:31.945326670Z","published":"2025-07-03T00:00:00Z","database_specific":{"cna_assigner":"mitre","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/45xxx/CVE-2025-45809.json","unresolved_ranges":[{"extracted_events":[{"fixed":"1.81.0"}],"source":"DESCRIPTION"}]},"references":[{"type":"WEB","url":"https://github.com/shadia0/Patienc/blob/main/litellm/SQL_injection.md"},{"type":"WEB","url":"https://huntr.com/bounties/3e6e4d40-b06a-4f54-a3ed-cc93584b12f3"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/45xxx/CVE-2025-45809.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-45809"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/berriai/litellm","events":[{"introduced":"b8597d3de4808fddaa44881f6253220c41c45183"},{"last_affected":"b8597d3de4808fddaa44881f6253220c41c45183"}],"database_specific":{"cpe":"cpe:2.3:a:litellm:litellm:1.65.4:*:*:*:*:*:*:*","extracted_events":[{"introduced":"1.65.4"},{"last_affected":"1.65.4"}],"source":"CPE_STRING"}}],"versions":["1.65.4","v1.65.4-stable"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-45809.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N"}]}