← signals
2026-08-13·LITELLM·security risk
meddown

Between 22–23 July 2026, four OSV/GHSA advisories disclosed critical vulnerabilities in LiteLLM, the open-source LLM...

Between 22–23 July 2026, four OSV/GHSA advisories disclosed critical vulnerabilities in LiteLLM, the open-source LLM gateway that claims 140+ provider integrations and 240M+ Docker pulls.

window 30devidence 10confidence score 100

confidence score

Strong evidence: 3 independent source classes support this read.

100
medium confidence3 independent source classesotherpasses publish gate

signal brief

Between 22–23 July 2026, four OSV/GHSA advisories disclosed critical vulnerabilities in LiteLLM, the open-source LLM gateway that claims 140+ provider integrations and 240M+ Docker pulls. The cluster includes CVE-2026-59819 (local file read via request-supplied OIDC file references), CVE-2026-59820 (arbitrary file write via path traversal in Skills archive extraction), CVE-2026-59821 (Custom Code Guardrails production endpoints bypass code safety checks), and CVE-2026-59822 (MCP Authentication Bypass via OAuth2 Passthrough Fallback). These advisories are published on OSV and aliased in PyPI security records.

The vulnerabilities are especially damaging given LiteLLM's market position. Its homepage markets the service as enterprise-grade with hard budgets, leaked-key protection, model access control, and audit logs, plus a new Rust-based gateway with sub-millisecond overhead. However, the Custom Code Guardrails bypass and MCP authentication bypass directly undermine the product's security guarantees. Arbitrary file write and local file read can expose sensitive configuration, secrets, or customer data in environments where LiteLLM handles prompts and API keys. For platform teams routing production LLM traffic, this is a trigger for security reviews, patch deployments, and potential procurement delays.

Timing also matters: the PyPI project shows a dev release (1.98.0.dev1) from 12 August 2026, indicating active development, but no public patch release is captured in these sources. Until fixes are validated, enterprise adoption momentum may stall. The absence of an official vendor response in the supplied sources adds uncertainty around remediation timing.

What the sources said

  • "LiteLLM: Local file read via request-supplied OIDC file references" — OSV advisory
  • "LiteLLM: Arbitrary file write via path traversal in Skills archive extraction" — OSV advisory
  • "LiteLLM: Custom Code Guardrails production endpoints bypass code safety checks" — OSV advisory
  • "LiteLLM: MCP Authentication Bypass via OAuth2 Passthrough Fallback" — OSV advisory
  • Context from the vendor site: "Self-host the same open-source gateway behind 240M+ Docker pulls" and "The LiteLLM Rust AI Gateway is live... adds 0.66 ms at p99" — litellm.ai

source data used

Decision support, not stock advice. This signal is research with cited evidence — not a recommendation to buy, sell, or hold any security.