A cluster of OSV/GitHub advisories (2026-07-13 and 2026-07-22) documents at least 12 distinct LiteLLM vulnerabilities,...
A cluster of OSV/GitHub advisories (2026-07-13 and 2026-07-22) documents at least 12 distinct LiteLLM vulnerabilities, including sandbox escape, authenticated RCE, privilege escalation, arbitrary file write/read, SSTI, and auth bypass.
confidence score
Strong evidence: 2 independent source classes support this read.
signal brief
A cluster of OSV/GitHub advisories (2026-07-13 and 2026-07-22) documents at least 12 distinct LiteLLM vulnerabilities, including sandbox escape, authenticated RCE, privilege escalation, arbitrary file write/read, SSTI, and auth bypass. LiteLLM is an LLM API gateway/proxy, so these are not merely library bugs: the gateway is a trusted interception point for model API keys, prompts, and traces.
Affected advisories: PYSEC-2026-2601 (sandbox escape in custom-code guardrail), PYSEC-2026-2599 (authenticated command execution via MCP stdio test endpoints), PYSEC-2026-2597 (privilege escalation via unrestricted proxy configuration endpoint), PYSEC-2026-2600 (user-role self-modification via /user/update), PYSEC-2026-2598 (API key route escalation for internal users), PYSEC-2026-2602 (SSTI in /prompts/test), PYSEC-2026-3476 (local file read via OIDC file references), PYSEC-2026-3477 (arbitrary file write via path traversal in Skills archive extraction), PYSEC-2026-3478 (guardrails production endpoints bypass code safety checks), PYSEC-2026-3479 (MCP auth bypass via OAuth2 passthrough fallback), plus the GHSA mirrors GHSA-4g5m-c9r5-49xf, GHSA-5jmr-gcrj-2c9q, GHSA-72m8-9m7m-h278, GHSA-7488-6r32-c95q. Meanwhile, litellm 1.95.1 was released on PyPI on 2026-08-09, but no fixed-version claim appears in the supplied events.
Why it matters: LiteLLM's proxy position means a single compromised deployment can leak API keys/traces, run arbitrary commands, and let low-privilege users elevate to admin. Enterprises running LiteLLM likely need emergency patching, audit, or temporary replacement — a concrete trust/compliance hit for the project and a friction point for AI-infra adoption.
What the sources said:
- "Sandbox escape in custom-code guardrail" — PYSEC-2026-2601
- "Authenticated command execution via MCP stdio test endpoints" — PYSEC-2026-2599
- "MCP Authentication Bypass via OAuth2 Passthrough Fallback" — GHSA-7488-6r32-c95q
- "Arbitrary file write via path traversal in Skills archive extraction" — PYSEC-2026-3477
source data used
“Library to easily interface with LLM API providers”
“Aliases: CVE-2026-59819, PYSEC-2026-3476 LiteLLM: Local file read via request-supplied OIDC file references”
“Aliases: CVE-2026-59820, PYSEC-2026-3477 LiteLLM: Arbitrary file write via path traversal in Skills archive extraction”
“Aliases: CVE-2026-59821, PYSEC-2026-3478 LiteLLM: Custom Code Guardrails production endpoints bypass code safety checks”
“Aliases: CVE-2026-59822, PYSEC-2026-3479 LiteLLM: MCP Authentication Bypass via OAuth2 Passthrough Fallback”
“Aliases: CVE-2026-35029, GHSA-53mr-6c8q-9789 LiteLLM: Privilege escalation via unrestricted proxy configuration endpoint”
“Aliases: CVE-2026-47101, GHSA-qrc4-49gv-mv9m LiteLLM allows an authenticated internal_user to create API keys with access to routes that their role does not permit”
“Aliases: CVE-2026-42271, GHSA-v4p8-mg3p-g94g LiteLLM: Authenticated command execution via MCP stdio test endpoints”
“Aliases: CVE-2026-47102, GHSA-wpfp-gwwc-vwq6 LiteLLM allows a user to modify their own user_role via the /user/update endpoint”
“Aliases: CVE-2026-40217, GHSA-wxxx-gvqv-xp7p LiteLLM has a sandbox escape in custom-code guardrail”
“Aliases: CVE-2026-42203, GHSA-xqmj-j6mv-4862 LiteLLM: Server-Side Template Injection in /prompts/test endpoint”
“Aliases: CVE-2026-59819, GHSA-4g5m-c9r5-49xf LiteLLM: Local file read via request-supplied OIDC file references”
“Aliases: CVE-2026-59820, GHSA-5jmr-gcrj-2c9q LiteLLM: Arbitrary file write via path traversal in Skills archive extraction”
“Aliases: CVE-2026-59821, GHSA-72m8-9m7m-h278 LiteLLM: Custom Code Guardrails production endpoints bypass code safety checks”
“Aliases: CVE-2026-59822, GHSA-7488-6r32-c95q LiteLLM: MCP Authentication Bypass via OAuth2 Passthrough Fallback”
Decision support, not stock advice. This signal is research with cited evidence — not a recommendation to buy, sell, or hold any security.