In July 2026, LiteLLM, an open-source library for interfacing with LLM API providers, was the subject of over 20...
In July 2026, LiteLLM, an open-source library for interfacing with LLM API providers, was the subject of over 20 security advisories published on OSV.dev.
confidence score
Strong evidence: 2 independent source classes support this read.
signal brief
In July 2026, LiteLLM, an open-source library for interfacing with LLM API providers, was the subject of over 20 security advisories published on OSV.dev. These advisories disclose critical vulnerabilities including remote code execution (CVE-2024-6825), arbitrary file read/write (CVE-2026-59819, CVE-2026-59820), authentication bypass (CVE-2026-59822, CVE-2026-49468), and SQL injection (CVE-2024-4890). The vulnerabilities span from June 29 to July 23, 2026, with a notable cluster on July 7 and July 13-23. A dev release (1.95.0.dev3) on PyPI (July 24) may contain fixes, but no stable patch has been released. The breadth and severity of these issues pose significant trust and security risks for enterprises using LiteLLM as a proxy for LLM calls, potentially driving users to alternative solutions. Source details: PyPI release, Advisory 1, Advisory 2, Advisory 3, Advisory 4, Advisory 5, Advisory 6, Advisory 7, Advisory 8, Advisory 9, Advisory 10, Advisory 11, Advisory 12, Advisory 13, Advisory 14, Advisory 15, Advisory 16, Advisory 17, Advisory 18, Advisory 19, Advisory 20, Advisory 21, Advisory 22, Advisory 23, Advisory 24, Advisory 25, Advisory 26, Advisory 27, Advisory 28, Advisory 29, Advisory 30, Advisory 31.
What the sources said
- "LiteLLM: Local file read via request-supplied OIDC file references" (CVE-2026-59819, GHSA-4g5m-c9r5-49xf)
- "LiteLLM Vulnerable to Remote Code Execution (RCE)" (CVE-2024-6825, PYSEC-2026-1541)
- "LiteLLM: Authentication Bypass via Host Header Injection" (CVE-2026-49468, PYSEC-2026-388)
- "LiteLLM: Custom Code Guardrails production endpoints bypass code safety checks" (CVE-2026-59821, GHSA-72m8-9m7m-h278)
source data used
“Library to easily interface with LLM API providers”
“Aliases: CVE-2026-59819, PYSEC-2026-3476 LiteLLM: Local file read via request-supplied OIDC file references”
“Aliases: CVE-2026-59820, PYSEC-2026-3477 LiteLLM: Arbitrary file write via path traversal in Skills archive extraction”
“Aliases: CVE-2026-59821, PYSEC-2026-3478 LiteLLM: Custom Code Guardrails production endpoints bypass code safety checks”
“Aliases: CVE-2026-59822, PYSEC-2026-3479 LiteLLM: MCP Authentication Bypass via OAuth2 Passthrough Fallback”
“Aliases: CVE-2024-4888, GHSA-3xr8-qfvj-9p9j Arbitrary file deletion in litellm”
“Aliases: CVE-2024-6825, GHSA-53gh-p8jc-7rg8 LiteLLM Vulnerable to Remote Code Execution (RCE)”
“Aliases: CVE-2024-4264, GHSA-7ggm-4rjg-594w litellm passes untrusted data to `eval` function without sanitization”
“Aliases: CVE-2025-0330, GHSA-879v-fggm-vxw2 LiteLLM Has a Leakage of Langfuse API Keys”
“Aliases: CVE-2024-4890, GHSA-8j42-pcfm-3467 SQL injection in litellm”
“Aliases: CVE-2024-8984, GHSA-fh2c-86xm-pm2x LiteLLM Vulnerable to Denial of Service (DoS) via Crafted HTTP Request”
“Aliases: CVE-2025-0628, GHSA-fjcf-3j3r-78rp LiteLLM Has an Improper Authorization Vulnerability”
“Aliases: CVE-2024-6587, GHSA-g26j-5385-hhw3 LiteLLM Server-Side Request Forgery (SSRF) vulnerability”
“Aliases: CVE-2024-9606, GHSA-g5pg-73fc-hjwq LiteLLM Reveals Portion of API Key via a Logging File”
“Aliases: CVE-2024-10188, GHSA-gw2q-qw9j-rgv7 LiteLLM Vulnerable to Denial of Service (DoS)”
“Aliases: CVE-2024-5225, GHSA-h6m6-jj8v-94jj SQL injection in litellm”
“Aliases: CVE-2024-5710, GHSA-qqcv-vg9f-5rr3 litellm vulnerable to improper access control in team management”
“Aliases: CVE-2026-35029, GHSA-53mr-6c8q-9789 LiteLLM: Privilege escalation via unrestricted proxy configuration endpoint”
“Aliases: CVE-2026-47101, GHSA-qrc4-49gv-mv9m LiteLLM allows an authenticated internal_user to create API keys with access to routes that their role does not permit”
“Aliases: CVE-2026-42271, GHSA-v4p8-mg3p-g94g LiteLLM: Authenticated command execution via MCP stdio test endpoints”
“Aliases: CVE-2026-47102, GHSA-wpfp-gwwc-vwq6 LiteLLM allows a user to modify their own user_role via the /user/update endpoint”
“Aliases: CVE-2026-40217, GHSA-wxxx-gvqv-xp7p LiteLLM has a sandbox escape in custom-code guardrail”
“Aliases: CVE-2026-42203, GHSA-xqmj-j6mv-4862 LiteLLM: Server-Side Template Injection in /prompts/test endpoint”
“Aliases: CVE-2026-59819, GHSA-4g5m-c9r5-49xf LiteLLM: Local file read via request-supplied OIDC file references”
“Aliases: CVE-2026-59820, GHSA-5jmr-gcrj-2c9q LiteLLM: Arbitrary file write via path traversal in Skills archive extraction”
“Aliases: CVE-2026-59821, GHSA-72m8-9m7m-h278 LiteLLM: Custom Code Guardrails production endpoints bypass code safety checks”
“Aliases: CVE-2026-59822, GHSA-7488-6r32-c95q LiteLLM: MCP Authentication Bypass via OAuth2 Passthrough Fallback”
“Aliases: CVE-2024-2952, GHSA-46cm-pfwv-cgf8 LiteLLM has Server-Side Template Injection vulnerability in /completions endpoint”
“Aliases: CVE-2026-49468, GHSA-4xpc-pv4p-pm3w LiteLLM: Authentication Bypass via Host Header Injection”
“Aliases: CVE-2024-5751, GHSA-gppg-gqw8-wh9g litellm vulnerable to remote code execution based on using eval unsafely”
“Aliases: CVE-2026-35030, GHSA-jjhc-v7c2-5hh6 LiteLLM: Authentication bypass via OIDC userinfo cache key collision”
“Aliases: CVE-2026-42208, GHSA-r75f-5x8p-qvmc LiteLLM has SQL Injection in Proxy API key verification”
Decision support, not stock advice. This signal is research with cited evidence — not a recommendation to buy, sell, or hold any security.