← signals
2026-07-20·LITELLM·security risk
highdown

LiteLLM, a popular library for interfacing with LLM API providers, has been hit by a wave of security vulnerability...

LiteLLM, a popular library for interfacing with LLM API providers, has been hit by a wave of security vulnerability advisories published on OSV between June 29 and July 13, 2026.

window 30devidence 24confidence score 100

confidence score

Strong evidence: 2 independent source classes support this read.

100
high confidence2 independent source classesotherpasses publish gate

signal brief

LiteLLM, a popular library for interfacing with LLM API providers, has been hit by a wave of security vulnerability advisories published on OSV between June 29 and July 13, 2026. The advisories cover at least 20 distinct CVEs, including Remote Code Execution (CVE-2024-6825, CVE-2024-5751), arbitrary file deletion (CVE-2024-4888), SQL injection (CVE-2024-4890, CVE-2024-5225), privilege escalation (CVE-2026-35029, CVE-2026-47101), authentication bypass (CVE-2026-49468, CVE-2026-35030), and server-side template injection (CVE-2026-42203, CVE-2024-2952). A new PyPI release v1.92.1 (2026-07-19) likely patches some of these, but the sheer volume and severity of the disclosures erode trust in the project. Users running self-hosted proxies or integrating LiteLLM into their pipelines face immediate risk of data breach, API key leakage, and system compromise. Enterprise adoption may slow as security teams re-evaluate the library's attack surface. The lack of a sandbox escape fix for custom-code guardrails (CVE-2026-40217) further undermines its trustworthiness in production environments.

What the sources said:

  • OSV advisory PYSEC-2026-1541: "LiteLLM Vulnerable to Remote Code Execution (RCE)"
  • OSV advisory PYSEC-2026-1544: "SQL injection in litellm"
  • OSV advisory PYSEC-2026-2597: "Privilege escalation via unrestricted proxy configuration endpoint"
  • OSV advisory PYSEC-2026-2601: "LiteLLM has a sandbox escape in custom-code guardrail"
  • PyPI release page: Version 1.92.1 released on 2026-07-19, likely addressing vulnerabilities.

source data used

Decision support, not stock advice. This signal is research with cited evidence — not a recommendation to buy, sell, or hold any security.