On 2026-07-13 and 2026-07-22/23, the OSV Vulnerability Database published a wave of advisories covering LiteLLM, the...
On 2026-07-13 and 2026-07-22/23, the OSV Vulnerability Database published a wave of advisories covering LiteLLM, the LLM proxy/gateway library.
confidence score
Strong evidence: 2 independent source classes support this read.
signal brief
On 2026-07-13 and 2026-07-22/23, the OSV Vulnerability Database published a wave of advisories covering LiteLLM, the LLM proxy/gateway library. These disclosures span critical categories: server-side template injection (PYSEC-2026-2602), sandbox escape in custom-code guardrails (PYSEC-2026-2601), arbitrary file write via path traversal in Skills archive extraction (GHSA-5jmr-gcrj-2c9q), local file read via request-supplied OIDC references (GHSA-4g5m-c9r5-49xf), MCP authentication bypass via OAuth2 passthrough fallback (GHSA-7488-6r32-c95q), authenticated command execution via MCP stdio test endpoints (CVE-2026-42271), privilege escalation via unrestricted proxy configuration endpoint (CVE-2026-35029), user role modification via /user/update (CVE-2026-47102), production endpoint guardrail bypass (GHSA-72m8-9m7m-h278), and internal user API key privilege escalation (CVE-2026-47101). A dev release (1.98.0.dev1) appeared on PyPI on 2026-08-12 (PyPI), but the advisories do not indicate a patched version.
For enterprises relying on LiteLLM as a central AI gateway, these vulnerabilities represent a serious trust and security risk. Attackers with low-privileged access could escalate privileges, modify API keys, read system files, or execute arbitrary commands. This should prompt security reviews and could slow enterprise adoption or shift customers to competing gateways.
What the sources said:
- PYSEC-2026-2601: "LiteLLM has a sandbox escape in custom-code guardrail"
- PYSEC-2026-2602: "LiteLLM: Server-Side Template Injection in /prompts/test endpoint"
- GHSA-4g5m-c9r5-49xf: "LiteLLM: Local file read via request-supplied OIDC file references"
- GHSA-7488-6r32-c95q: "LiteLLM: MCP Authentication Bypass via OAuth2 Passthrough Fallback"
source data used
“Library to easily interface with LLM API providers”
“Aliases: CVE-2026-59819, PYSEC-2026-3476 LiteLLM: Local file read via request-supplied OIDC file references”
“Aliases: CVE-2026-59820, PYSEC-2026-3477 LiteLLM: Arbitrary file write via path traversal in Skills archive extraction”
“Aliases: CVE-2026-59821, PYSEC-2026-3478 LiteLLM: Custom Code Guardrails production endpoints bypass code safety checks”
“Aliases: CVE-2026-59822, PYSEC-2026-3479 LiteLLM: MCP Authentication Bypass via OAuth2 Passthrough Fallback”
“Aliases: CVE-2026-35029, GHSA-53mr-6c8q-9789 LiteLLM: Privilege escalation via unrestricted proxy configuration endpoint”
“Aliases: CVE-2026-47101, GHSA-qrc4-49gv-mv9m LiteLLM allows an authenticated internal_user to create API keys with access to routes that their role does not permit”
“Aliases: CVE-2026-42271, GHSA-v4p8-mg3p-g94g LiteLLM: Authenticated command execution via MCP stdio test endpoints”
“Aliases: CVE-2026-47102, GHSA-wpfp-gwwc-vwq6 LiteLLM allows a user to modify their own user_role via the /user/update endpoint”
“Aliases: CVE-2026-40217, GHSA-wxxx-gvqv-xp7p LiteLLM has a sandbox escape in custom-code guardrail”
“Aliases: CVE-2026-42203, GHSA-xqmj-j6mv-4862 LiteLLM: Server-Side Template Injection in /prompts/test endpoint”
“Aliases: CVE-2026-59819, GHSA-4g5m-c9r5-49xf LiteLLM: Local file read via request-supplied OIDC file references”
“Aliases: CVE-2026-59820, GHSA-5jmr-gcrj-2c9q LiteLLM: Arbitrary file write via path traversal in Skills archive extraction”
“Aliases: CVE-2026-59821, GHSA-72m8-9m7m-h278 LiteLLM: Custom Code Guardrails production endpoints bypass code safety checks”
“Aliases: CVE-2026-59822, GHSA-7488-6r32-c95q LiteLLM: MCP Authentication Bypass via OAuth2 Passthrough Fallback”
Decision support, not stock advice. This signal is research with cited evidence — not a recommendation to buy, sell, or hold any security.