mirror of
https://github.com/BerriAI/litellm.git
synced 2026-10-07 02:59:05 +00:00
key_alias becomes the secret name written to HashiCorp Vault and CyberArk Conjur when store_virtual_keys is enabled. Vault's get_url concatenated secret_name directly into the request URL and Conjur's _ensure_variable_exists interpolated it unescaped into a YAML policy body, so a malicious key_alias could path-traverse the Vault write or inject extra Conjur policy statements. The only existing guard was opt-in (enable_key_alias_format_validation, default off) and its charset still permitted ".." even when enabled. Add raise_if_unsafe_secret_name, an unconditional check rejecting ".." sequences and control characters (including the Unicode line breaks YAML treats the same as "\n": NEL, LINE SEPARATOR, PARAGRAPH SEPARATOR), applied at both vulnerable sinks and at the API boundary in _validate_key_alias_format, independent of the opt-in flag. Also close two adjacent gaps found in internal review: Vault's get_url now percent-encodes secret_name (preserving "/" and "@") so "#"/"?" can't turn into a URL fragment/query string instead of a literal path segment, and Conjur's policy YAML is now built with a real YAML serializer (yaml.safe_dump forced to double-quoted style) instead of raw string interpolation, so metacharacters that aren't on the traversal/control-char denylist (a bare ":" or "#") can no longer change the parsed policy structure. |
||
|---|---|---|
| .. | ||
| base_token_counter_test.py | ||
| conftest.py | ||
| log.txt | ||
| test_aiohttp_handler.py | ||
| test_anthropic_token_counter.py | ||
| test_aws_secret_manager.py | ||
| test_azure_ai_anthropic_token_counter.py | ||
| test_bedrock_token_counter.py | ||
| test_cyberark.py | ||
| test_get_secret.py | ||
| test_hashicorp.py | ||
| test_health_check.py | ||
| test_litellm_overhead.py | ||
| test_logging_callback_manager.py | ||
| test_proxy_budget_reset.py | ||
| test_secret_manager.py | ||
| test_utils.py | ||
| test_validate_tool_choice.py | ||
| vertex_key.json | ||