Sync packaging to live v1.84.0 deployment (CVE-2026-35029/59822 fix line)
- Dockerfile: pin ghcr.io/berriai/litellm:v1.84.0 (was floating main-v1.74.0-stable, which silently moved to a newer digest). v1.84.0 is the fix line for CVE-2026-35029 (auth bypass on /config/update, fixed 1.83.0) and CVE-2026-59822 (MCP session auth bypass, fixed 1.84.0, CISA KEV). - Drop the v1.74.0-era sed CORS patch: upstream v1.84.0 moved the file and now reads LITELLM_CORS_ORIGINS natively. - start.sh: export LITELLM_CORS_ORIGINS (the native v1.84.0 var) instead of LITELLM_CORS_ALLOWED_ORIGINS (the old sed-patch var that v1.84.0 ignores) — keeps CORS locked to chat.inference.coop. - CloudronManifest: upstreamVersion 1.74.0 -> 1.84.0. Live gateway already runs v1.84.0 (image digest sha256:dc532d896ba8..., built 2026-10-02 04:50 UTC); this commit makes the repo mirror the deployed packaging per the no-drift rule. LITELLM_CORS_ORIGINS also set as a Cloudron env var on the app so the running container honours it without a rebuild.
This commit is contained in:
1 parent
8f42be988e
commit
fd34e33508
3 files changed
+18
-14
No files matched your search
+10
-8
@@ -1,4 +1,9 @@
|
||||
FROM ghcr.io/berriai/litellm:main-v1.74.0-stable
|
||||
FROM ghcr.io/berriai/litellm:v1.84.0
|
||||
|
||||
# v1.84.0 is the fix line for CVE-2026-35029 (auth bypass on
|
||||
# /config/update, fixed 1.83.0) and CVE-2026-59822 (MCP session auth
|
||||
# bypass, fixed 1.84.0, CISA KEV catalog). Pin the exact tag — do NOT
|
||||
# use a floating tag like main-v1.74.0-stable, which silently moved.
|
||||
|
||||
# LiteLLM's official image runs as root. Cloudron's sandboxing (read-only
|
||||
# rootfs, AppArmor, dropped capabilities) still applies to root inside the
|
||||
@@ -19,10 +24,7 @@ COPY config.yaml /app/data/config.yaml
|
||||
# startup script runs instead of being passed as an argument to litellm.
|
||||
ENTRYPOINT ["/app/code/start.sh"]
|
||||
|
||||
# LiteLLM v1.74.0 hardcodes `origins = ["*"]` (with allow_credentials=True) in
|
||||
# proxy_server.py and ignores LITELLM_CORS_ALLOWED_ORIGINS entirely. Rewrite it
|
||||
# to honour the env var so we can lock CORS to the chat origin. Patch every copy
|
||||
# (site-packages is what the running CLI imports; /app/litellm is a dev copy).
|
||||
RUN sed -i 's/^origins = \["\*"\]$/import os; origins = os.getenv("LITELLM_CORS_ALLOWED_ORIGINS", "*").split(",")/' \
|
||||
/usr/lib/python3.13/site-packages/litellm/proxy/proxy_server.py \
|
||||
/app/litellm/proxy/proxy_server.py
|
||||
# No CORS patch needed since v1.84.0: upstream replaced the hardcoded
|
||||
# `origins = ["*"]` with a native LITELLM_CORS_ORIGINS env var (start.sh
|
||||
# exports it). The old sed patch targeted a v1.74.0 file layout that no
|
||||
# longer exists — the v1.84.0 rebuild self-skipped it correctly.
|
||||
Reference in new issue
Block a user