Between July 7 and July 23, 2026, OSV.dev published a wave of security advisories affecting LiteLLM, the open-source...
Between July 7 and July 23, 2026, OSV.dev published a wave of security advisories affecting LiteLLM, the open-source LLM gateway/proxy widely used in AI infrastructure to route requests to multiple providers.
confidence score
Strong evidence: 2 independent source classes support this read.
signal brief
Between July 7 and July 23, 2026, OSV.dev published a wave of security advisories affecting LiteLLM, the open-source LLM gateway/proxy widely used in AI infrastructure to route requests to multiple providers. The disclosures include critical vulnerabilities: CVE-2026-59819 local file read via OIDC file references (GHSA-4g5m-c9r5-49xf), CVE-2026-59820 arbitrary file write via path traversal (GHSA-5jmr-gcrj-2c9q), CVE-2026-59821 bypass of custom code guardrails (GHSA-72m8-9m7m-h278), and CVE-2026-59822 MCP authentication bypass via OAuth2 fallback (GHSA-7488-6r32-c95q). Earlier July advisories also covered remote code execution (CVE-2024-6825), SQL injection, SSRF, and API key leakage. Many of these are rated high severity and expose both hosted and self-managed LiteLLM instances to compromise. A new PyPI release litellm 1.95.0 appeared on Aug 2, 2026, but its description only says 'Library to easily interface with LLM API providers' with no explicit patch notes in the source. The cluster of vulnerabilities suggests a pattern of security debt that may undermine enterprise trust in LiteLLM as a secure AI gateway, potentially affecting adoption among enterprises and regulated industries. For AI infrastructure watchers, this is a concrete security_risk signal for the entity.
What the sources said
- "LiteLLM: Local file read via request-supplied OIDC file references" — GHSA-4g5m-c9r5-49xf
- "LiteLLM: Custom Code Guardrails production endpoints bypass code safety checks" — GHSA-72m8-9m7m-h278
- "LiteLLM: MCP Authentication Bypass via OAuth2 Passthrough Fallback" — GHSA-7488-6r32-c95q
- "LiteLLM Vulnerable to Remote Code Execution (RCE)" — PYSEC-2026-1541
source data used
“Library to easily interface with LLM API providers”
“Aliases: CVE-2026-59819, PYSEC-2026-3476 LiteLLM: Local file read via request-supplied OIDC file references”
“Aliases: CVE-2026-59820, PYSEC-2026-3477 LiteLLM: Arbitrary file write via path traversal in Skills archive extraction”
“Aliases: CVE-2026-59821, PYSEC-2026-3478 LiteLLM: Custom Code Guardrails production endpoints bypass code safety checks”
“Aliases: CVE-2026-59822, PYSEC-2026-3479 LiteLLM: MCP Authentication Bypass via OAuth2 Passthrough Fallback”
“Aliases: CVE-2024-4888, GHSA-3xr8-qfvj-9p9j Arbitrary file deletion in litellm”
“Aliases: CVE-2024-6825, GHSA-53gh-p8jc-7rg8 LiteLLM Vulnerable to Remote Code Execution (RCE)”
“Aliases: CVE-2024-4264, GHSA-7ggm-4rjg-594w litellm passes untrusted data to `eval` function without sanitization”
“Aliases: CVE-2025-0330, GHSA-879v-fggm-vxw2 LiteLLM Has a Leakage of Langfuse API Keys”
“Aliases: CVE-2024-4890, GHSA-8j42-pcfm-3467 SQL injection in litellm”
“Aliases: CVE-2024-8984, GHSA-fh2c-86xm-pm2x LiteLLM Vulnerable to Denial of Service (DoS) via Crafted HTTP Request”
“Aliases: CVE-2025-0628, GHSA-fjcf-3j3r-78rp LiteLLM Has an Improper Authorization Vulnerability”
“Aliases: CVE-2024-6587, GHSA-g26j-5385-hhw3 LiteLLM Server-Side Request Forgery (SSRF) vulnerability”
“Aliases: CVE-2024-9606, GHSA-g5pg-73fc-hjwq LiteLLM Reveals Portion of API Key via a Logging File”
“Aliases: CVE-2024-10188, GHSA-gw2q-qw9j-rgv7 LiteLLM Vulnerable to Denial of Service (DoS)”
“Aliases: CVE-2024-5225, GHSA-h6m6-jj8v-94jj SQL injection in litellm”
“Aliases: CVE-2024-5710, GHSA-qqcv-vg9f-5rr3 litellm vulnerable to improper access control in team management”
“Aliases: CVE-2026-35029, GHSA-53mr-6c8q-9789 LiteLLM: Privilege escalation via unrestricted proxy configuration endpoint”
“Aliases: CVE-2026-47101, GHSA-qrc4-49gv-mv9m LiteLLM allows an authenticated internal_user to create API keys with access to routes that their role does not permit”
“Aliases: CVE-2026-42271, GHSA-v4p8-mg3p-g94g LiteLLM: Authenticated command execution via MCP stdio test endpoints”
“Aliases: CVE-2026-47102, GHSA-wpfp-gwwc-vwq6 LiteLLM allows a user to modify their own user_role via the /user/update endpoint”
“Aliases: CVE-2026-40217, GHSA-wxxx-gvqv-xp7p LiteLLM has a sandbox escape in custom-code guardrail”
“Aliases: CVE-2026-42203, GHSA-xqmj-j6mv-4862 LiteLLM: Server-Side Template Injection in /prompts/test endpoint”
“Aliases: CVE-2026-59819, GHSA-4g5m-c9r5-49xf LiteLLM: Local file read via request-supplied OIDC file references”
“Aliases: CVE-2026-59820, GHSA-5jmr-gcrj-2c9q LiteLLM: Arbitrary file write via path traversal in Skills archive extraction”
“Aliases: CVE-2026-59821, GHSA-72m8-9m7m-h278 LiteLLM: Custom Code Guardrails production endpoints bypass code safety checks”
“Aliases: CVE-2026-59822, GHSA-7488-6r32-c95q LiteLLM: MCP Authentication Bypass via OAuth2 Passthrough Fallback”
Decision support, not stock advice. This signal is research with cited evidence — not a recommendation to buy, sell, or hold any security.