← signals
2026-08-09·LITELLM·security risk
meddown

Between July 13 and July 23, OSV published eleven security advisories for LiteLLM, the widely-used LLM proxy/gateway.

Between July 13 and July 23, OSV published eleven security advisories for LiteLLM, the widely-used LLM proxy/gateway.

window 10devidence 15confidence score 100

confidence score

Strong evidence: 2 independent source classes support this read.

100
medium confidence2 independent source classesotherpasses publish gate

signal brief

Between July 13 and July 23, OSV published eleven security advisories for LiteLLM, the widely-used LLM proxy/gateway. The vulnerabilities span high-severity classes: local file read via request-supplied OIDC file references (GHSA-4g5m-c9r5-49xf / CVE-2026-59819), arbitrary file write via path traversal in Skills archive extraction (GHSA-5jmr-gcrj-2c9q / CVE-2026-59820), bypass of Custom Code Guardrails safety checks in production endpoints (GHSA-72m8-9m7m-h278 / CVE-2026-59821), MCP authentication bypass via OAuth2 passthrough fallback (GHSA-7488-6r32-c95q / CVE-2026-59822), privilege escalation via unrestricted proxy config endpoint (PYSEC-2026-2597 / CVE-2026-35029), API key privilege escalation for internal users (PYSEC-2026-2598 / CVE-2026-47101), authenticated command execution via MCP stdio test endpoints (PYSEC-2026-2599 / CVE-2026-42271), self role modification via /user/update (PYSEC-2026-2600 / CVE-2026-47102), sandbox escape in custom-code guardrail (PYSEC-2026-2601 / CVE-2026-40217), and server-side template injection in /prompts/test endpoint (PYSEC-2026-2602 / CVE-2026-42203). These advisories are also mirrored in PYSEC entries with the same CVEs. The August 9 PyPI release of litellm 1.95.1 shows continued maintenance but no explicit security-fix notes in the release description. For organizations running LiteLLM as a central gateway for LLM API access, these issues could allow attackers to read local files, write arbitrary files, execute commands, or bypass authentication/authorization. The cluster of advisories signals a security posture that may require immediate patching or vendor reassessment.

What the sources said:

  • "LiteLLM: Local file read via request-supplied OIDC file references" — https://osv.dev/vulnerability/GHSA-4g5m-c9r5-49xf
  • "LiteLLM: Arbitrary file write via path traversal in Skills archive extraction" — https://osv.dev/vulnerability/GHSA-5jmr-gcrj-2c9q
  • "LiteLLM: MCP Authentication Bypass via OAuth2 Passthrough Fallback" — https://osv.dev/vulnerability/GHSA-7488-6r32-c95q
  • "LiteLLM: Authenticated command execution via MCP stdio test endpoints" — https://osv.dev/vulnerability/PYSEC-2026-2599

source data used

Decision support, not stock advice. This signal is research with cited evidence — not a recommendation to buy, sell, or hold any security.