Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CVE-2024-6119: Locked litellm version #2042

Open
tojaroslaw opened this issue Jan 13, 2025 · 0 comments
Open

CVE-2024-6119: Locked litellm version #2042

tojaroslaw opened this issue Jan 13, 2025 · 0 comments

Comments

@tojaroslaw
Copy link

Hi dspy team!

I was trying to upgrade the version of litellm we use because older versions are vulnerable to CVE-2024-6119. This is fixed in versions 1.56.2 and above. However, I could not upgrade litellm because the latest versions of dspy lock the version of litellm to a lower value. I noticed that in the latest, unreleased version of the requirements file on the master branch, the version was changed to 1.57.4 which would solve the problem when dspy 2.6.0 is released.

I was wondering if it would be possible to upgrade this in version 2.5 and release a version 2.5.44 that allows us to patch this vulnerability. If that's not do-able, I was wondering if the team had a rough timeline for when dspy 2.6.0 would be released? Even another pre-release might help us if gets the job done.

Thanks!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant