← signals
2026-08-10·LITELLM·security risk
highdown

A cluster of OSV/GitHub advisories (2026-07-13 and 2026-07-22) documents at least 12 distinct LiteLLM vulnerabilities,...

A cluster of OSV/GitHub advisories (2026-07-13 and 2026-07-22) documents at least 12 distinct LiteLLM vulnerabilities, including sandbox escape, authenticated RCE, privilege escalation, arbitrary file write/read, SSTI, and auth bypass.

window 15devidence 15confidence score 100

confidence score

Strong evidence: 2 independent source classes support this read.

100
high confidence2 independent source classesotherpasses publish gate

signal brief

A cluster of OSV/GitHub advisories (2026-07-13 and 2026-07-22) documents at least 12 distinct LiteLLM vulnerabilities, including sandbox escape, authenticated RCE, privilege escalation, arbitrary file write/read, SSTI, and auth bypass. LiteLLM is an LLM API gateway/proxy, so these are not merely library bugs: the gateway is a trusted interception point for model API keys, prompts, and traces.

Affected advisories: PYSEC-2026-2601 (sandbox escape in custom-code guardrail), PYSEC-2026-2599 (authenticated command execution via MCP stdio test endpoints), PYSEC-2026-2597 (privilege escalation via unrestricted proxy configuration endpoint), PYSEC-2026-2600 (user-role self-modification via /user/update), PYSEC-2026-2598 (API key route escalation for internal users), PYSEC-2026-2602 (SSTI in /prompts/test), PYSEC-2026-3476 (local file read via OIDC file references), PYSEC-2026-3477 (arbitrary file write via path traversal in Skills archive extraction), PYSEC-2026-3478 (guardrails production endpoints bypass code safety checks), PYSEC-2026-3479 (MCP auth bypass via OAuth2 passthrough fallback), plus the GHSA mirrors GHSA-4g5m-c9r5-49xf, GHSA-5jmr-gcrj-2c9q, GHSA-72m8-9m7m-h278, GHSA-7488-6r32-c95q. Meanwhile, litellm 1.95.1 was released on PyPI on 2026-08-09, but no fixed-version claim appears in the supplied events.

Why it matters: LiteLLM's proxy position means a single compromised deployment can leak API keys/traces, run arbitrary commands, and let low-privilege users elevate to admin. Enterprises running LiteLLM likely need emergency patching, audit, or temporary replacement — a concrete trust/compliance hit for the project and a friction point for AI-infra adoption.

What the sources said:

source data used

Decision support, not stock advice. This signal is research with cited evidence — not a recommendation to buy, sell, or hold any security.