← signals
2026-08-01·LITELLM·security risk
meddown

A wave of security advisories has been published against LiteLLM, the popular open-source LLM gateway/proxy, between...

A wave of security advisories has been published against LiteLLM, the popular open-source LLM gateway/proxy, between 2026-07-07 and 2026-07-23.

window 30devidence 27confidence score 100

confidence score

Strong evidence: 2 independent source classes support this read.

100
medium confidence2 independent source classesotherpasses publish gate

signal brief

A wave of security advisories has been published against LiteLLM, the popular open-source LLM gateway/proxy, between 2026-07-07 and 2026-07-23. The primary entity is LiteLLM, and the cluster materially weakens its enterprise trust profile.

Evidence walkthrough: OSV.dev published multiple GHSA/PYSEC entries. As of 2026-07-22/23, four new advisories were added (GHSA-4g5m-c9r5-49xf, GHSA-5jmr-gcrj-2c9q, GHSA-72m8-9m7m-h278, GHSA-7488-6r32-c95q) covering local file read, arbitrary file write via path traversal, guardrail bypass, and MCP authentication bypass. Prior to that, on 2026-07-13, a set of severe issues were published including privilege escalation (PYSEC-2026-2597), command execution via MCP stdio endpoints (PYSEC-2026-2599), sandbox escape in custom-code guardrails (PYSEC-2026-2601), and server-side template injection (PYSEC-2026-2602). Older CVEs (2024-2025) were also backfilled, including RCE (PYSEC-2026-1541) and SQL injection (PYSEC-2026-1544). A PyPI release candidate (litellm 1.95.0rc3) exists as of 2026-08-01, suggesting fixes are in motion, but the volume and severity of disclosed vulnerabilities will raise eyebrows in enterprise security reviews.

What the sources said:

  • "LiteLLM: Local file read via request-supplied OIDC file references" — GHSA-4g5m-c9r5-49xf
  • "LiteLLM: Arbitrary file write via path traversal in Skills archive extraction" — GHSA-5jmr-gcrj-2c9q
  • "LiteLLM: MCP Authentication Bypass via OAuth2 Passthrough Fallback" — GHSA-7488-6r32-c95q
  • "LiteLLM has a sandbox escape in custom-code guardrail" — PYSEC-2026-2601

Direction rationale: The bull case is that active patching and an aggressive release cadence mitigate long-term damage. The bear case is stronger: a concentrated disclosure of RCE, auth bypass, and sandbox escape flaws in a security-critical control plane will lengthen enterprise procurement cycles, trigger SSO/guardrail scrutiny, and open the door for competitors. Therefore direction is down for LiteLLM's near-term adoption momentum.

source data used

Decision support, not stock advice. This signal is research with cited evidence — not a recommendation to buy, sell, or hold any security.