Skip to content

[Issue]: LiteLLM version used has a CVE #2331

@NameIsTimYes

Description

@NameIsTimYes

Do you need to file an issue?

  • I have searched the existing issues and this bug is not already filed.
  • My model is hosted on OpenAI or Azure. If not, please look at the "model providers" issue and don't file a new one here.
  • I believe this is a legitimate bug, not just a question. If this is a question, please use the Discussions area.

Describe the issue

  1. Graphrag currently uses litellm==1.82.6 as a dependency.
  2. This version has three high to critical vulnerabilities:
  3. The guidance is to upgrade to 1.83.10,

As far as I can see there should probably be no problems upgrading to this version.

Steps to reproduce

No response

GraphRAG Config Used

# Paste your config here

Logs and screenshots

No response

Additional Information

No response

Metadata

Metadata

Assignees

No one assigned

    Labels

    triageDefault label assignment, indicates new issue needs reviewed by a maintainer

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions