← signals
2026-07-21·LITELLM·security risk
meddown

Between June 29 and July 13, 2026, the Open Source Vulnerability (OSV) database published 24 CVEs affecting LiteLLM, a...

Between June 29 and July 13, 2026, the Open Source Vulnerability (OSV) database published 24 CVEs affecting LiteLLM, a popular open-source LLM proxy library.

window 30devidence 24confidence score 100

confidence score

Strong evidence: 2 independent source classes support this read.

100
medium confidence2 independent source classesotherpasses publish gate

signal brief

Between June 29 and July 13, 2026, the Open Source Vulnerability (OSV) database published 24 CVEs affecting LiteLLM, a popular open-source LLM proxy library. The vulnerabilities include critical flaws such as remote code execution (CVE-2024-6825), arbitrary file deletion (CVE-2024-4888), SQL injection (CVE-2024-4890), authentication bypass (CVE-2026-49468), privilege escalation (CVE-2026-35029), and sandbox escape (CVE-2026-40217). Notably, multiple CVEs involve unsanitized eval usage leading to RCE, and API key leakage via logging. The concentrated disclosure of 24 distinct vulnerabilities in a short period signals significant security debt and could erode trust among enterprise adopters. While a release candidate (1.94.0rc2) was published on PyPI, it is unclear if it addresses all disclosed flaws. The scope and severity suggest that organizations using LiteLLM in production may need to reassess their risk posture.

What the sources said:

source data used

Decision support, not stock advice. This signal is research with cited evidence — not a recommendation to buy, sell, or hold any security.