← signals
2026-08-12·LITELLM·security risk
meddown

On 2026-07-13 and 2026-07-22/23, the OSV Vulnerability Database published a wave of advisories covering LiteLLM, the...

On 2026-07-13 and 2026-07-22/23, the OSV Vulnerability Database published a wave of advisories covering LiteLLM, the LLM proxy/gateway library.

window 15devidence 15confidence score 100

confidence score

Strong evidence: 2 independent source classes support this read.

100
medium confidence2 independent source classesotherpasses publish gate

signal brief

On 2026-07-13 and 2026-07-22/23, the OSV Vulnerability Database published a wave of advisories covering LiteLLM, the LLM proxy/gateway library. These disclosures span critical categories: server-side template injection (PYSEC-2026-2602), sandbox escape in custom-code guardrails (PYSEC-2026-2601), arbitrary file write via path traversal in Skills archive extraction (GHSA-5jmr-gcrj-2c9q), local file read via request-supplied OIDC references (GHSA-4g5m-c9r5-49xf), MCP authentication bypass via OAuth2 passthrough fallback (GHSA-7488-6r32-c95q), authenticated command execution via MCP stdio test endpoints (CVE-2026-42271), privilege escalation via unrestricted proxy configuration endpoint (CVE-2026-35029), user role modification via /user/update (CVE-2026-47102), production endpoint guardrail bypass (GHSA-72m8-9m7m-h278), and internal user API key privilege escalation (CVE-2026-47101). A dev release (1.98.0.dev1) appeared on PyPI on 2026-08-12 (PyPI), but the advisories do not indicate a patched version.

For enterprises relying on LiteLLM as a central AI gateway, these vulnerabilities represent a serious trust and security risk. Attackers with low-privileged access could escalate privileges, modify API keys, read system files, or execute arbitrary commands. This should prompt security reviews and could slow enterprise adoption or shift customers to competing gateways.

What the sources said:

source data used

Decision support, not stock advice. This signal is research with cited evidence — not a recommendation to buy, sell, or hold any security.