In July 2026, LiteLLM, a popular open-source library for interfacing with LLM API providers, was disclosed to have over...
In July 2026, LiteLLM, a popular open-source library for interfacing with LLM API providers, was disclosed to have over 20 critical and high-severity vulnerabilities across multiple advisories on OSV.dev.
confidence score
Strong evidence: 2 independent source classes support this read.
signal brief
In July 2026, LiteLLM, a popular open-source library for interfacing with LLM API providers, was disclosed to have over 20 critical and high-severity vulnerabilities across multiple advisories on OSV.dev. The vulnerabilities include local file read (CVE-2026-59819), arbitrary file write (CVE-2026-59820), remote code execution (CVE-2024-6825, CVE-2024-5751), SQL injection (CVE-2024-4890, CVE-2024-5225), authentication bypass (CVE-2026-49468, CVE-2026-35030), privilege escalation (CVE-2026-35029, CVE-2026-47101), and sandbox escape (CVE-2026-40217). The volume and severity of these vulnerabilities could significantly erode developer trust in LiteLLM as a secure proxy for LLM interactions. Enterprise users may delay adoption or seek alternatives. While a development release (1.95.0.dev2) appeared on PyPI on July 24, there is no stable patch yet for many advisories published in late July.
What the sources said:
- OSV GHSA-4g5m-c9r5-49xf: "LiteLLM: Local file read via request-supplied OIDC file references"
- OSV GHSA-5jmr-gcrj-2c9q: "LiteLLM: Arbitrary file write via path traversal in Skills archive extraction"
- OSV GHSA-72m8-9m7m-h278: "LiteLLM: Custom Code Guardrails production endpoints bypass code safety checks"
- OSV GHSA-7488-6r32-c95q: "LiteLLM: MCP Authentication Bypass via OAuth2 Passthrough Fallback"
- OSV PYSEC-2026-1541: "LiteLLM Vulnerable to Remote Code Execution (RCE)"
source data used
“Library to easily interface with LLM API providers”
“Aliases: CVE-2026-59819, PYSEC-2026-3476 LiteLLM: Local file read via request-supplied OIDC file references”
“Aliases: CVE-2026-59820, PYSEC-2026-3477 LiteLLM: Arbitrary file write via path traversal in Skills archive extraction”
“Aliases: CVE-2026-59821, PYSEC-2026-3478 LiteLLM: Custom Code Guardrails production endpoints bypass code safety checks”
“Aliases: CVE-2026-59822, PYSEC-2026-3479 LiteLLM: MCP Authentication Bypass via OAuth2 Passthrough Fallback”
“Aliases: CVE-2024-4888, GHSA-3xr8-qfvj-9p9j Arbitrary file deletion in litellm”
“Aliases: CVE-2024-6825, GHSA-53gh-p8jc-7rg8 LiteLLM Vulnerable to Remote Code Execution (RCE)”
“Aliases: CVE-2024-4264, GHSA-7ggm-4rjg-594w litellm passes untrusted data to `eval` function without sanitization”
“Aliases: CVE-2025-0330, GHSA-879v-fggm-vxw2 LiteLLM Has a Leakage of Langfuse API Keys”
“Aliases: CVE-2024-4890, GHSA-8j42-pcfm-3467 SQL injection in litellm”
“Aliases: CVE-2024-8984, GHSA-fh2c-86xm-pm2x LiteLLM Vulnerable to Denial of Service (DoS) via Crafted HTTP Request”
“Aliases: CVE-2025-0628, GHSA-fjcf-3j3r-78rp LiteLLM Has an Improper Authorization Vulnerability”
“Aliases: CVE-2024-6587, GHSA-g26j-5385-hhw3 LiteLLM Server-Side Request Forgery (SSRF) vulnerability”
“Aliases: CVE-2024-9606, GHSA-g5pg-73fc-hjwq LiteLLM Reveals Portion of API Key via a Logging File”
“Aliases: CVE-2024-10188, GHSA-gw2q-qw9j-rgv7 LiteLLM Vulnerable to Denial of Service (DoS)”
“Aliases: CVE-2024-5225, GHSA-h6m6-jj8v-94jj SQL injection in litellm”
“Aliases: CVE-2024-5710, GHSA-qqcv-vg9f-5rr3 litellm vulnerable to improper access control in team management”
“Aliases: CVE-2026-35029, GHSA-53mr-6c8q-9789 LiteLLM: Privilege escalation via unrestricted proxy configuration endpoint”
“Aliases: CVE-2026-47101, GHSA-qrc4-49gv-mv9m LiteLLM allows an authenticated internal_user to create API keys with access to routes that their role does not permit”
“Aliases: CVE-2026-42271, GHSA-v4p8-mg3p-g94g LiteLLM: Authenticated command execution via MCP stdio test endpoints”
“Aliases: CVE-2026-47102, GHSA-wpfp-gwwc-vwq6 LiteLLM allows a user to modify their own user_role via the /user/update endpoint”
“Aliases: CVE-2026-40217, GHSA-wxxx-gvqv-xp7p LiteLLM has a sandbox escape in custom-code guardrail”
“Aliases: CVE-2026-42203, GHSA-xqmj-j6mv-4862 LiteLLM: Server-Side Template Injection in /prompts/test endpoint”
“Aliases: CVE-2026-59819, GHSA-4g5m-c9r5-49xf LiteLLM: Local file read via request-supplied OIDC file references”
“Aliases: CVE-2026-59820, GHSA-5jmr-gcrj-2c9q LiteLLM: Arbitrary file write via path traversal in Skills archive extraction”
“Aliases: CVE-2026-59821, GHSA-72m8-9m7m-h278 LiteLLM: Custom Code Guardrails production endpoints bypass code safety checks”
“Aliases: CVE-2026-59822, GHSA-7488-6r32-c95q LiteLLM: MCP Authentication Bypass via OAuth2 Passthrough Fallback”
“Aliases: CVE-2024-2952, GHSA-46cm-pfwv-cgf8 LiteLLM has Server-Side Template Injection vulnerability in /completions endpoint”
“Aliases: CVE-2026-49468, GHSA-4xpc-pv4p-pm3w LiteLLM: Authentication Bypass via Host Header Injection”
“Aliases: CVE-2024-5751, GHSA-gppg-gqw8-wh9g litellm vulnerable to remote code execution based on using eval unsafely”
“Aliases: CVE-2026-35030, GHSA-jjhc-v7c2-5hh6 LiteLLM: Authentication bypass via OIDC userinfo cache key collision”
“Aliases: CVE-2026-42208, GHSA-r75f-5x8p-qvmc LiteLLM has SQL Injection in Proxy API key verification”
Decision support, not stock advice. This signal is research with cited evidence — not a recommendation to buy, sell, or hold any security.