Merge pull request #3193 from BerriAI/litellm_sec_fix_delete_files

[Fix] - `/audio/transcriptions` security fix
This commit is contained in:
Ishaan Jaff 2024-04-20 12:26:02 -07:00 committed by GitHub
commit 0dc7f02b51
No known key found for this signature in database
GPG key ID: B5690EEEBB952194

View file

@ -4166,6 +4166,14 @@ async def audio_transcriptions(
file.filename is not None
) # make sure filename passed in (needed for type)
_original_filename = file.filename
file_extension = os.path.splitext(file.filename)[1]
# rename the file to a random hash file name -> we eventuall remove the file and don't want to remove any local files
file.filename = f"tmp-request" + str(uuid.uuid4()) + file_extension
# IMP - Asserts that we've renamed the uploaded file, since we run os.remove(file.filename), we should rename the original file
assert file.filename != _original_filename
with open(file.filename, "wb+") as f:
f.write(await file.read())
try: