Signal
A cluster of security advisories was published against LiteLLM (the popular LLM gateway/proxy) between July 13 and July 23, 2026, including CVE-2026-59819 through CVE-2026-59822.
confidence score
Strong evidence: 2 independent source classes support this read.
signal brief
Signal
A cluster of security advisories was published against LiteLLM (the popular LLM gateway/proxy) between July 13 and July 23, 2026, including CVE-2026-59819 through CVE-2026-59822. These cover local file read via OIDC file references, arbitrary file write via path traversal in Skills archive extraction, bypass of Custom Code Guardrails safety checks, and MCP authentication bypass via OAuth2 passthrough fallback. Additional earlier advisories (CVE-2026-35029, CVE-2026-47101, CVE-2026-42271, CVE-2026-47102, CVE-2026-40217, CVE-2026-42203) describe privilege escalation, authenticated command execution, self-role modification, sandbox escape in custom-code guardrails, and server-side template injection in /prompts/test.
These are not low-impact bugs: the file read and write vulnerabilities can expose secrets or overwrite configuration in environments that run LiteLLM, while the guardrail bypass and sandbox escape undermine the safety guarantees of custom code guardrails. The MCP auth bypass could allow unauthenticated access to connected model context protocol servers. For enterprise AI infrastructure, LiteLLM is often deployed as the central gateway, so a CVE cluster of this scale raises immediate supply-chain risk and may accelerate reviews of alternative proxies.
A new PyPI release (litellm 1.96.1) appeared on August 11, 2026, but the advisories do not explicitly confirm which fixes are included. Even with a patch, the trust impact is negative: security teams may require urgent upgrades, and some users may hesitate to continue using LiteLLM in production.
What the sources said
- OSV GHSA-4g5m-c9r5-49xf: "LiteLLM: Local file read via request-supplied OIDC file references"
- OSV GHSA-5jmr-gcrj-2c9q: "LiteLLM: Arbitrary file write via path traversal in Skills archive extraction"
- OSV GHSA-72m8-9m7m-h278: "LiteLLM: Custom Code Guardrails production endpoints bypass code safety checks"
- OSV PYSEC-2026-2599: "LiteLLM: Authenticated command execution via MCP stdio test endpoints"
This cluster materially changes the risk profile of a core piece of AI infrastructure software. Enterprises running LiteLLM should expect scrutiny and potential delays in expanding its deployment until patched versions are proven in production.
source data used
“Library to easily interface with LLM API providers”
“Aliases: CVE-2026-59819, PYSEC-2026-3476 LiteLLM: Local file read via request-supplied OIDC file references”
“Aliases: CVE-2026-59820, PYSEC-2026-3477 LiteLLM: Arbitrary file write via path traversal in Skills archive extraction”
“Aliases: CVE-2026-59821, PYSEC-2026-3478 LiteLLM: Custom Code Guardrails production endpoints bypass code safety checks”
“Aliases: CVE-2026-59822, PYSEC-2026-3479 LiteLLM: MCP Authentication Bypass via OAuth2 Passthrough Fallback”
“Aliases: CVE-2026-35029, GHSA-53mr-6c8q-9789 LiteLLM: Privilege escalation via unrestricted proxy configuration endpoint”
“Aliases: CVE-2026-47101, GHSA-qrc4-49gv-mv9m LiteLLM allows an authenticated internal_user to create API keys with access to routes that their role does not permit”
“Aliases: CVE-2026-42271, GHSA-v4p8-mg3p-g94g LiteLLM: Authenticated command execution via MCP stdio test endpoints”
“Aliases: CVE-2026-47102, GHSA-wpfp-gwwc-vwq6 LiteLLM allows a user to modify their own user_role via the /user/update endpoint”
“Aliases: CVE-2026-40217, GHSA-wxxx-gvqv-xp7p LiteLLM has a sandbox escape in custom-code guardrail”
“Aliases: CVE-2026-42203, GHSA-xqmj-j6mv-4862 LiteLLM: Server-Side Template Injection in /prompts/test endpoint”
“Aliases: CVE-2026-59819, GHSA-4g5m-c9r5-49xf LiteLLM: Local file read via request-supplied OIDC file references”
“Aliases: CVE-2026-59820, GHSA-5jmr-gcrj-2c9q LiteLLM: Arbitrary file write via path traversal in Skills archive extraction”
“Aliases: CVE-2026-59821, GHSA-72m8-9m7m-h278 LiteLLM: Custom Code Guardrails production endpoints bypass code safety checks”
“Aliases: CVE-2026-59822, GHSA-7488-6r32-c95q LiteLLM: MCP Authentication Bypass via OAuth2 Passthrough Fallback”
Decision support, not stock advice. This signal is research with cited evidence — not a recommendation to buy, sell, or hold any security.