← signals
2026-07-26·LITELLM·security risk
meddown

In July 2026, LiteLLM, an open-source library for interfacing with LLM API providers, was the subject of over 20...

In July 2026, LiteLLM, an open-source library for interfacing with LLM API providers, was the subject of over 20 security advisories published on OSV.dev.

window 30devidence 32confidence score 100

confidence score

Strong evidence: 2 independent source classes support this read.

100
medium confidence2 independent source classesotherpasses publish gate

signal brief

In July 2026, LiteLLM, an open-source library for interfacing with LLM API providers, was the subject of over 20 security advisories published on OSV.dev. These advisories disclose critical vulnerabilities including remote code execution (CVE-2024-6825), arbitrary file read/write (CVE-2026-59819, CVE-2026-59820), authentication bypass (CVE-2026-59822, CVE-2026-49468), and SQL injection (CVE-2024-4890). The vulnerabilities span from June 29 to July 23, 2026, with a notable cluster on July 7 and July 13-23. A dev release (1.95.0.dev3) on PyPI (July 24) may contain fixes, but no stable patch has been released. The breadth and severity of these issues pose significant trust and security risks for enterprises using LiteLLM as a proxy for LLM calls, potentially driving users to alternative solutions. Source details: PyPI release, Advisory 1, Advisory 2, Advisory 3, Advisory 4, Advisory 5, Advisory 6, Advisory 7, Advisory 8, Advisory 9, Advisory 10, Advisory 11, Advisory 12, Advisory 13, Advisory 14, Advisory 15, Advisory 16, Advisory 17, Advisory 18, Advisory 19, Advisory 20, Advisory 21, Advisory 22, Advisory 23, Advisory 24, Advisory 25, Advisory 26, Advisory 27, Advisory 28, Advisory 29, Advisory 30, Advisory 31.

What the sources said

  • "LiteLLM: Local file read via request-supplied OIDC file references" (CVE-2026-59819, GHSA-4g5m-c9r5-49xf)
  • "LiteLLM Vulnerable to Remote Code Execution (RCE)" (CVE-2024-6825, PYSEC-2026-1541)
  • "LiteLLM: Authentication Bypass via Host Header Injection" (CVE-2026-49468, PYSEC-2026-388)
  • "LiteLLM: Custom Code Guardrails production endpoints bypass code safety checks" (CVE-2026-59821, GHSA-72m8-9m7m-h278)

source data used

Decision support, not stock advice. This signal is research with cited evidence — not a recommendation to buy, sell, or hold any security.