Between July 13 and July 23, OSV published eleven security advisories for LiteLLM, the widely-used LLM proxy/gateway.
Between July 13 and July 23, OSV published eleven security advisories for LiteLLM, the widely-used LLM proxy/gateway.
confidence score
Strong evidence: 2 independent source classes support this read.
signal brief
Between July 13 and July 23, OSV published eleven security advisories for LiteLLM, the widely-used LLM proxy/gateway. The vulnerabilities span high-severity classes: local file read via request-supplied OIDC file references (GHSA-4g5m-c9r5-49xf / CVE-2026-59819), arbitrary file write via path traversal in Skills archive extraction (GHSA-5jmr-gcrj-2c9q / CVE-2026-59820), bypass of Custom Code Guardrails safety checks in production endpoints (GHSA-72m8-9m7m-h278 / CVE-2026-59821), MCP authentication bypass via OAuth2 passthrough fallback (GHSA-7488-6r32-c95q / CVE-2026-59822), privilege escalation via unrestricted proxy config endpoint (PYSEC-2026-2597 / CVE-2026-35029), API key privilege escalation for internal users (PYSEC-2026-2598 / CVE-2026-47101), authenticated command execution via MCP stdio test endpoints (PYSEC-2026-2599 / CVE-2026-42271), self role modification via /user/update (PYSEC-2026-2600 / CVE-2026-47102), sandbox escape in custom-code guardrail (PYSEC-2026-2601 / CVE-2026-40217), and server-side template injection in /prompts/test endpoint (PYSEC-2026-2602 / CVE-2026-42203). These advisories are also mirrored in PYSEC entries with the same CVEs. The August 9 PyPI release of litellm 1.95.1 shows continued maintenance but no explicit security-fix notes in the release description. For organizations running LiteLLM as a central gateway for LLM API access, these issues could allow attackers to read local files, write arbitrary files, execute commands, or bypass authentication/authorization. The cluster of advisories signals a security posture that may require immediate patching or vendor reassessment.
What the sources said:
- "LiteLLM: Local file read via request-supplied OIDC file references" — https://osv.dev/vulnerability/GHSA-4g5m-c9r5-49xf
- "LiteLLM: Arbitrary file write via path traversal in Skills archive extraction" — https://osv.dev/vulnerability/GHSA-5jmr-gcrj-2c9q
- "LiteLLM: MCP Authentication Bypass via OAuth2 Passthrough Fallback" — https://osv.dev/vulnerability/GHSA-7488-6r32-c95q
- "LiteLLM: Authenticated command execution via MCP stdio test endpoints" — https://osv.dev/vulnerability/PYSEC-2026-2599
source data used
“Library to easily interface with LLM API providers”
“Aliases: CVE-2026-59819, PYSEC-2026-3476 LiteLLM: Local file read via request-supplied OIDC file references”
“Aliases: CVE-2026-59820, PYSEC-2026-3477 LiteLLM: Arbitrary file write via path traversal in Skills archive extraction”
“Aliases: CVE-2026-59821, PYSEC-2026-3478 LiteLLM: Custom Code Guardrails production endpoints bypass code safety checks”
“Aliases: CVE-2026-59822, PYSEC-2026-3479 LiteLLM: MCP Authentication Bypass via OAuth2 Passthrough Fallback”
“Aliases: CVE-2026-35029, GHSA-53mr-6c8q-9789 LiteLLM: Privilege escalation via unrestricted proxy configuration endpoint”
“Aliases: CVE-2026-47101, GHSA-qrc4-49gv-mv9m LiteLLM allows an authenticated internal_user to create API keys with access to routes that their role does not permit”
“Aliases: CVE-2026-42271, GHSA-v4p8-mg3p-g94g LiteLLM: Authenticated command execution via MCP stdio test endpoints”
“Aliases: CVE-2026-47102, GHSA-wpfp-gwwc-vwq6 LiteLLM allows a user to modify their own user_role via the /user/update endpoint”
“Aliases: CVE-2026-40217, GHSA-wxxx-gvqv-xp7p LiteLLM has a sandbox escape in custom-code guardrail”
“Aliases: CVE-2026-42203, GHSA-xqmj-j6mv-4862 LiteLLM: Server-Side Template Injection in /prompts/test endpoint”
“Aliases: CVE-2026-59819, GHSA-4g5m-c9r5-49xf LiteLLM: Local file read via request-supplied OIDC file references”
“Aliases: CVE-2026-59820, GHSA-5jmr-gcrj-2c9q LiteLLM: Arbitrary file write via path traversal in Skills archive extraction”
“Aliases: CVE-2026-59821, GHSA-72m8-9m7m-h278 LiteLLM: Custom Code Guardrails production endpoints bypass code safety checks”
“Aliases: CVE-2026-59822, GHSA-7488-6r32-c95q LiteLLM: MCP Authentication Bypass via OAuth2 Passthrough Fallback”
Decision support, not stock advice. This signal is research with cited evidence — not a recommendation to buy, sell, or hold any security.