Between 22–23 July 2026, four OSV/GHSA advisories disclosed critical vulnerabilities in LiteLLM, the open-source LLM...
Between 22–23 July 2026, four OSV/GHSA advisories disclosed critical vulnerabilities in LiteLLM, the open-source LLM gateway that claims 140+ provider integrations and 240M+ Docker pulls.
confidence score
Strong evidence: 3 independent source classes support this read.
signal brief
Between 22–23 July 2026, four OSV/GHSA advisories disclosed critical vulnerabilities in LiteLLM, the open-source LLM gateway that claims 140+ provider integrations and 240M+ Docker pulls. The cluster includes CVE-2026-59819 (local file read via request-supplied OIDC file references), CVE-2026-59820 (arbitrary file write via path traversal in Skills archive extraction), CVE-2026-59821 (Custom Code Guardrails production endpoints bypass code safety checks), and CVE-2026-59822 (MCP Authentication Bypass via OAuth2 Passthrough Fallback). These advisories are published on OSV and aliased in PyPI security records.
The vulnerabilities are especially damaging given LiteLLM's market position. Its homepage markets the service as enterprise-grade with hard budgets, leaked-key protection, model access control, and audit logs, plus a new Rust-based gateway with sub-millisecond overhead. However, the Custom Code Guardrails bypass and MCP authentication bypass directly undermine the product's security guarantees. Arbitrary file write and local file read can expose sensitive configuration, secrets, or customer data in environments where LiteLLM handles prompts and API keys. For platform teams routing production LLM traffic, this is a trigger for security reviews, patch deployments, and potential procurement delays.
Timing also matters: the PyPI project shows a dev release (1.98.0.dev1) from 12 August 2026, indicating active development, but no public patch release is captured in these sources. Until fixes are validated, enterprise adoption momentum may stall. The absence of an official vendor response in the supplied sources adds uncertainty around remediation timing.
What the sources said
- "LiteLLM: Local file read via request-supplied OIDC file references" — OSV advisory
- "LiteLLM: Arbitrary file write via path traversal in Skills archive extraction" — OSV advisory
- "LiteLLM: Custom Code Guardrails production endpoints bypass code safety checks" — OSV advisory
- "LiteLLM: MCP Authentication Bypass via OAuth2 Passthrough Fallback" — OSV advisory
- Context from the vendor site: "Self-host the same open-source gateway behind 240M+ Docker pulls" and "The LiteLLM Rust AI Gateway is live... adds 0.66 ms at p99" — litellm.ai
source data used
“The AI Gateway for platform teams Self-host in minutes. No credit card. “LiteLLM gives NVIDIA engineers a single, consistent way to access more than 100 AI model endpoints.” “LiteLLM streamlines the complexities of managing multiple LLM...”
“Library to easily interface with LLM API providers”
“Aliases: CVE-2026-59819, PYSEC-2026-3476 LiteLLM: Local file read via request-supplied OIDC file references”
“Aliases: CVE-2026-59820, PYSEC-2026-3477 LiteLLM: Arbitrary file write via path traversal in Skills archive extraction”
“Aliases: CVE-2026-59821, PYSEC-2026-3478 LiteLLM: Custom Code Guardrails production endpoints bypass code safety checks”
“Aliases: CVE-2026-59822, PYSEC-2026-3479 LiteLLM: MCP Authentication Bypass via OAuth2 Passthrough Fallback”
“Aliases: CVE-2026-59819, GHSA-4g5m-c9r5-49xf LiteLLM: Local file read via request-supplied OIDC file references”
“Aliases: CVE-2026-59820, GHSA-5jmr-gcrj-2c9q LiteLLM: Arbitrary file write via path traversal in Skills archive extraction”
“Aliases: CVE-2026-59821, GHSA-72m8-9m7m-h278 LiteLLM: Custom Code Guardrails production endpoints bypass code safety checks”
“Aliases: CVE-2026-59822, GHSA-7488-6r32-c95q LiteLLM: MCP Authentication Bypass via OAuth2 Passthrough Fallback”
Decision support, not stock advice. This signal is research with cited evidence — not a recommendation to buy, sell, or hold any security.