← signals
2026-08-11·LITELLM·security risk
highdown

Signal

A cluster of security advisories was published against LiteLLM (the popular LLM gateway/proxy) between July 13 and July 23, 2026, including CVE-2026-59819 through CVE-2026-59822.

window 15devidence 15confidence score 100

confidence score

Strong evidence: 2 independent source classes support this read.

100
high confidence2 independent source classesotherpasses publish gate

signal brief

Signal

A cluster of security advisories was published against LiteLLM (the popular LLM gateway/proxy) between July 13 and July 23, 2026, including CVE-2026-59819 through CVE-2026-59822. These cover local file read via OIDC file references, arbitrary file write via path traversal in Skills archive extraction, bypass of Custom Code Guardrails safety checks, and MCP authentication bypass via OAuth2 passthrough fallback. Additional earlier advisories (CVE-2026-35029, CVE-2026-47101, CVE-2026-42271, CVE-2026-47102, CVE-2026-40217, CVE-2026-42203) describe privilege escalation, authenticated command execution, self-role modification, sandbox escape in custom-code guardrails, and server-side template injection in /prompts/test.

These are not low-impact bugs: the file read and write vulnerabilities can expose secrets or overwrite configuration in environments that run LiteLLM, while the guardrail bypass and sandbox escape undermine the safety guarantees of custom code guardrails. The MCP auth bypass could allow unauthenticated access to connected model context protocol servers. For enterprise AI infrastructure, LiteLLM is often deployed as the central gateway, so a CVE cluster of this scale raises immediate supply-chain risk and may accelerate reviews of alternative proxies.

A new PyPI release (litellm 1.96.1) appeared on August 11, 2026, but the advisories do not explicitly confirm which fixes are included. Even with a patch, the trust impact is negative: security teams may require urgent upgrades, and some users may hesitate to continue using LiteLLM in production.

What the sources said

This cluster materially changes the risk profile of a core piece of AI infrastructure software. Enterprises running LiteLLM should expect scrutiny and potential delays in expanding its deployment until patched versions are proven in production.

source data used

Decision support, not stock advice. This signal is research with cited evidence — not a recommendation to buy, sell, or hold any security.