← signals
2026-08-03·LITELLM·security risk
highdown

Between July 7 and July 23, 2026, OSV.dev published a wave of security advisories affecting LiteLLM, the open-source...

Between July 7 and July 23, 2026, OSV.dev published a wave of security advisories affecting LiteLLM, the open-source LLM gateway/proxy widely used in AI infrastructure to route requests to multiple providers.

window 15devidence 27confidence score 100

confidence score

Strong evidence: 2 independent source classes support this read.

100
high confidence2 independent source classesotherpasses publish gate

signal brief

Between July 7 and July 23, 2026, OSV.dev published a wave of security advisories affecting LiteLLM, the open-source LLM gateway/proxy widely used in AI infrastructure to route requests to multiple providers. The disclosures include critical vulnerabilities: CVE-2026-59819 local file read via OIDC file references (GHSA-4g5m-c9r5-49xf), CVE-2026-59820 arbitrary file write via path traversal (GHSA-5jmr-gcrj-2c9q), CVE-2026-59821 bypass of custom code guardrails (GHSA-72m8-9m7m-h278), and CVE-2026-59822 MCP authentication bypass via OAuth2 fallback (GHSA-7488-6r32-c95q). Earlier July advisories also covered remote code execution (CVE-2024-6825), SQL injection, SSRF, and API key leakage. Many of these are rated high severity and expose both hosted and self-managed LiteLLM instances to compromise. A new PyPI release litellm 1.95.0 appeared on Aug 2, 2026, but its description only says 'Library to easily interface with LLM API providers' with no explicit patch notes in the source. The cluster of vulnerabilities suggests a pattern of security debt that may undermine enterprise trust in LiteLLM as a secure AI gateway, potentially affecting adoption among enterprises and regulated industries. For AI infrastructure watchers, this is a concrete security_risk signal for the entity.

What the sources said

source data used

Decision support, not stock advice. This signal is research with cited evidence — not a recommendation to buy, sell, or hold any security.