← signals
2026-07-27·LITELLM·security risk
highdown

Between June 29 and July 24, 2026, over two dozen new security advisories for LiteLLM were published on OSV.dev,...

Between June 29 and July 24, 2026, over two dozen new security advisories for LiteLLM were published on OSV.dev, including remote code execution, SQL injection, authentication bypass, and privilege escalation flaws.

window 30devidence 32confidence score 100

confidence score

Strong evidence: 2 independent source classes support this read.

100
high confidence2 independent source classesotherpasses publish gate

signal brief

Between June 29 and July 24, 2026, over two dozen new security advisories for LiteLLM were published on OSV.dev, including remote code execution, SQL injection, authentication bypass, and privilege escalation flaws. The volume and severity indicate a systemic security issue in the project. On July 24, a dev release (1.95.0.dev3) was pushed to PyPI, likely containing fixes, but the rapid disclosure of vulnerabilities (e.g., CVE-2026-59819 through CVE-2026-59822 on July 22, plus earlier batches) suggests ongoing discovery of critical holes. Enterprises relying on LiteLLM as a proxy layer for LLM APIs may face increased risk and may delay adoption or seek alternatives.

What the sources said:

  • OSV advisory CVE-2026-59819: "LiteLLM: Local file read via request-supplied OIDC file references" Source 2
  • OSV advisory CVE-2026-59820: "LiteLLM: Arbitrary file write via path traversal in Skills archive extraction" Source 3
  • OSV advisory CVE-2026-59821: "LiteLLM: Custom Code Guardrails production endpoints bypass code safety checks" Source 4
  • OSV advisory CVE-2026-59822: "LiteLLM: MCP Authentication Bypass via OAuth2 Passthrough Fallback" Source 5
  • Earlier advisories include RCE, SQLi, and SSRF vulnerabilities Sources 6-17 through 17.

source data used

Decision support, not stock advice. This signal is research with cited evidence — not a recommendation to buy, sell, or hold any security.