A wave of security advisories has been published against LiteLLM, the popular open-source LLM gateway/proxy, between...
A wave of security advisories has been published against LiteLLM, the popular open-source LLM gateway/proxy, between 2026-07-07 and 2026-07-23.
confidence score
Strong evidence: 2 independent source classes support this read.
signal brief
A wave of security advisories has been published against LiteLLM, the popular open-source LLM gateway/proxy, between 2026-07-07 and 2026-07-23. The primary entity is LiteLLM, and the cluster materially weakens its enterprise trust profile.
Evidence walkthrough: OSV.dev published multiple GHSA/PYSEC entries. As of 2026-07-22/23, four new advisories were added (GHSA-4g5m-c9r5-49xf, GHSA-5jmr-gcrj-2c9q, GHSA-72m8-9m7m-h278, GHSA-7488-6r32-c95q) covering local file read, arbitrary file write via path traversal, guardrail bypass, and MCP authentication bypass. Prior to that, on 2026-07-13, a set of severe issues were published including privilege escalation (PYSEC-2026-2597), command execution via MCP stdio endpoints (PYSEC-2026-2599), sandbox escape in custom-code guardrails (PYSEC-2026-2601), and server-side template injection (PYSEC-2026-2602). Older CVEs (2024-2025) were also backfilled, including RCE (PYSEC-2026-1541) and SQL injection (PYSEC-2026-1544). A PyPI release candidate (litellm 1.95.0rc3) exists as of 2026-08-01, suggesting fixes are in motion, but the volume and severity of disclosed vulnerabilities will raise eyebrows in enterprise security reviews.
What the sources said:
- "LiteLLM: Local file read via request-supplied OIDC file references" — GHSA-4g5m-c9r5-49xf
- "LiteLLM: Arbitrary file write via path traversal in Skills archive extraction" — GHSA-5jmr-gcrj-2c9q
- "LiteLLM: MCP Authentication Bypass via OAuth2 Passthrough Fallback" — GHSA-7488-6r32-c95q
- "LiteLLM has a sandbox escape in custom-code guardrail" — PYSEC-2026-2601
Direction rationale: The bull case is that active patching and an aggressive release cadence mitigate long-term damage. The bear case is stronger: a concentrated disclosure of RCE, auth bypass, and sandbox escape flaws in a security-critical control plane will lengthen enterprise procurement cycles, trigger SSO/guardrail scrutiny, and open the door for competitors. Therefore direction is down for LiteLLM's near-term adoption momentum.
source data used
“Library to easily interface with LLM API providers”
“Aliases: CVE-2026-59819, PYSEC-2026-3476 LiteLLM: Local file read via request-supplied OIDC file references”
“Aliases: CVE-2026-59820, PYSEC-2026-3477 LiteLLM: Arbitrary file write via path traversal in Skills archive extraction”
“Aliases: CVE-2026-59821, PYSEC-2026-3478 LiteLLM: Custom Code Guardrails production endpoints bypass code safety checks”
“Aliases: CVE-2026-59822, PYSEC-2026-3479 LiteLLM: MCP Authentication Bypass via OAuth2 Passthrough Fallback”
“Aliases: CVE-2024-4888, GHSA-3xr8-qfvj-9p9j Arbitrary file deletion in litellm”
“Aliases: CVE-2024-6825, GHSA-53gh-p8jc-7rg8 LiteLLM Vulnerable to Remote Code Execution (RCE)”
“Aliases: CVE-2024-4264, GHSA-7ggm-4rjg-594w litellm passes untrusted data to `eval` function without sanitization”
“Aliases: CVE-2025-0330, GHSA-879v-fggm-vxw2 LiteLLM Has a Leakage of Langfuse API Keys”
“Aliases: CVE-2024-4890, GHSA-8j42-pcfm-3467 SQL injection in litellm”
“Aliases: CVE-2024-8984, GHSA-fh2c-86xm-pm2x LiteLLM Vulnerable to Denial of Service (DoS) via Crafted HTTP Request”
“Aliases: CVE-2025-0628, GHSA-fjcf-3j3r-78rp LiteLLM Has an Improper Authorization Vulnerability”
“Aliases: CVE-2024-6587, GHSA-g26j-5385-hhw3 LiteLLM Server-Side Request Forgery (SSRF) vulnerability”
“Aliases: CVE-2024-9606, GHSA-g5pg-73fc-hjwq LiteLLM Reveals Portion of API Key via a Logging File”
“Aliases: CVE-2024-10188, GHSA-gw2q-qw9j-rgv7 LiteLLM Vulnerable to Denial of Service (DoS)”
“Aliases: CVE-2024-5225, GHSA-h6m6-jj8v-94jj SQL injection in litellm”
“Aliases: CVE-2024-5710, GHSA-qqcv-vg9f-5rr3 litellm vulnerable to improper access control in team management”
“Aliases: CVE-2026-35029, GHSA-53mr-6c8q-9789 LiteLLM: Privilege escalation via unrestricted proxy configuration endpoint”
“Aliases: CVE-2026-47101, GHSA-qrc4-49gv-mv9m LiteLLM allows an authenticated internal_user to create API keys with access to routes that their role does not permit”
“Aliases: CVE-2026-42271, GHSA-v4p8-mg3p-g94g LiteLLM: Authenticated command execution via MCP stdio test endpoints”
“Aliases: CVE-2026-47102, GHSA-wpfp-gwwc-vwq6 LiteLLM allows a user to modify their own user_role via the /user/update endpoint”
“Aliases: CVE-2026-40217, GHSA-wxxx-gvqv-xp7p LiteLLM has a sandbox escape in custom-code guardrail”
“Aliases: CVE-2026-42203, GHSA-xqmj-j6mv-4862 LiteLLM: Server-Side Template Injection in /prompts/test endpoint”
“Aliases: CVE-2026-59819, GHSA-4g5m-c9r5-49xf LiteLLM: Local file read via request-supplied OIDC file references”
“Aliases: CVE-2026-59820, GHSA-5jmr-gcrj-2c9q LiteLLM: Arbitrary file write via path traversal in Skills archive extraction”
“Aliases: CVE-2026-59821, GHSA-72m8-9m7m-h278 LiteLLM: Custom Code Guardrails production endpoints bypass code safety checks”
“Aliases: CVE-2026-59822, GHSA-7488-6r32-c95q LiteLLM: MCP Authentication Bypass via OAuth2 Passthrough Fallback”
Decision support, not stock advice. This signal is research with cited evidence — not a recommendation to buy, sell, or hold any security.