Multiple OSV advisories (Jul 7-23, 2026) disclosed over 30 CVEs in LiteLLM, the popular LLM API proxy.
Multiple OSV advisories (Jul 7-23, 2026) disclosed over 30 CVEs in LiteLLM, the popular LLM API proxy.
confidence score
Strong evidence: 2 independent source classes support this read.
signal brief
Multiple OSV advisories (Jul 7-23, 2026) disclosed over 30 CVEs in LiteLLM, the popular LLM API proxy. Vulnerabilities include remote code execution (CVE-2024-6825), SQL injection (CVE-2024-4890), server-side request forgery (CVE-2024-6587), and authentication bypass via OIDC (CVE-2026-59819). The breadth of issues—from arbitrary file write to privilege escalation—signals systemic code quality problems. A new PyPI release (1.93.1) on Jul 29 likely patches many of these, but the disclosure cluster damages developer confidence. Enterprises relying on LiteLLM for production LLM routing face urgent patching and reassessment.
What the sources said:
- "LiteLLM: Local file read via request-supplied OIDC file references" (GHSA-4g5m-c9r5-49xf).
- "LiteLLM Vulnerable to Remote Code Execution (RCE)" (PYSEC-2026-1541).
- "LiteLLM: Authentication bypass via OIDC userinfo cache key collision" (GHSA-jjhc-v7c2-5hh6).
- "library to easily interface with LLM API providers" (PyPI release 1.93.1).
source data used
“Library to easily interface with LLM API providers”
“Aliases: CVE-2026-59819, PYSEC-2026-3476 LiteLLM: Local file read via request-supplied OIDC file references”
“Aliases: CVE-2026-59820, PYSEC-2026-3477 LiteLLM: Arbitrary file write via path traversal in Skills archive extraction”
“Aliases: CVE-2026-59821, PYSEC-2026-3478 LiteLLM: Custom Code Guardrails production endpoints bypass code safety checks”
“Aliases: CVE-2026-59822, PYSEC-2026-3479 LiteLLM: MCP Authentication Bypass via OAuth2 Passthrough Fallback”
“Aliases: CVE-2024-4888, GHSA-3xr8-qfvj-9p9j Arbitrary file deletion in litellm”
“Aliases: CVE-2024-6825, GHSA-53gh-p8jc-7rg8 LiteLLM Vulnerable to Remote Code Execution (RCE)”
“Aliases: CVE-2024-4264, GHSA-7ggm-4rjg-594w litellm passes untrusted data to `eval` function without sanitization”
“Aliases: CVE-2025-0330, GHSA-879v-fggm-vxw2 LiteLLM Has a Leakage of Langfuse API Keys”
“Aliases: CVE-2024-4890, GHSA-8j42-pcfm-3467 SQL injection in litellm”
“Aliases: CVE-2024-8984, GHSA-fh2c-86xm-pm2x LiteLLM Vulnerable to Denial of Service (DoS) via Crafted HTTP Request”
“Aliases: CVE-2025-0628, GHSA-fjcf-3j3r-78rp LiteLLM Has an Improper Authorization Vulnerability”
“Aliases: CVE-2024-6587, GHSA-g26j-5385-hhw3 LiteLLM Server-Side Request Forgery (SSRF) vulnerability”
“Aliases: CVE-2024-9606, GHSA-g5pg-73fc-hjwq LiteLLM Reveals Portion of API Key via a Logging File”
“Aliases: CVE-2024-10188, GHSA-gw2q-qw9j-rgv7 LiteLLM Vulnerable to Denial of Service (DoS)”
“Aliases: CVE-2024-5225, GHSA-h6m6-jj8v-94jj SQL injection in litellm”
“Aliases: CVE-2024-5710, GHSA-qqcv-vg9f-5rr3 litellm vulnerable to improper access control in team management”
“Aliases: CVE-2026-35029, GHSA-53mr-6c8q-9789 LiteLLM: Privilege escalation via unrestricted proxy configuration endpoint”
“Aliases: CVE-2026-47101, GHSA-qrc4-49gv-mv9m LiteLLM allows an authenticated internal_user to create API keys with access to routes that their role does not permit”
“Aliases: CVE-2026-42271, GHSA-v4p8-mg3p-g94g LiteLLM: Authenticated command execution via MCP stdio test endpoints”
“Aliases: CVE-2026-47102, GHSA-wpfp-gwwc-vwq6 LiteLLM allows a user to modify their own user_role via the /user/update endpoint”
“Aliases: CVE-2026-40217, GHSA-wxxx-gvqv-xp7p LiteLLM has a sandbox escape in custom-code guardrail”
“Aliases: CVE-2026-42203, GHSA-xqmj-j6mv-4862 LiteLLM: Server-Side Template Injection in /prompts/test endpoint”
“Aliases: CVE-2026-59819, GHSA-4g5m-c9r5-49xf LiteLLM: Local file read via request-supplied OIDC file references”
“Aliases: CVE-2026-59820, GHSA-5jmr-gcrj-2c9q LiteLLM: Arbitrary file write via path traversal in Skills archive extraction”
“Aliases: CVE-2026-59821, GHSA-72m8-9m7m-h278 LiteLLM: Custom Code Guardrails production endpoints bypass code safety checks”
“Aliases: CVE-2026-59822, GHSA-7488-6r32-c95q LiteLLM: MCP Authentication Bypass via OAuth2 Passthrough Fallback”
“Aliases: CVE-2024-2952, GHSA-46cm-pfwv-cgf8 LiteLLM has Server-Side Template Injection vulnerability in /completions endpoint”
“Aliases: CVE-2026-49468, GHSA-4xpc-pv4p-pm3w LiteLLM: Authentication Bypass via Host Header Injection”
“Aliases: CVE-2024-5751, GHSA-gppg-gqw8-wh9g litellm vulnerable to remote code execution based on using eval unsafely”
“Aliases: CVE-2026-35030, GHSA-jjhc-v7c2-5hh6 LiteLLM: Authentication bypass via OIDC userinfo cache key collision”
“Aliases: CVE-2026-42208, GHSA-r75f-5x8p-qvmc LiteLLM has SQL Injection in Proxy API key verification”
Decision support, not stock advice. This signal is research with cited evidence — not a recommendation to buy, sell, or hold any security.