LiteLLM: Local file read via request-supplied OIDC file references
PYSEC-2026-3476 · CVE-2026-59819 · GHSA-4g5m-c9r5-49xf
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
Impact
LiteLLM's /health/test_connection endpoint resolved request-supplied environment and OIDC file references in litellm_params. A proxy administrator, or another privileged caller with permission to test model connections, could cause LiteLLM to read files from the local filesystem via an oidc/file/ reference.
Because exploitation requires privileged proxy access, this is treated as a defense-in-depth issue rather than a cross-tenant privilege bypass.
Patches
The issue is fixed in 1.83.10-stable.
LiteLLM recommend upgrading to 1.83.10-stable or later.
Workarounds
Restrict /health/test_connection access to trusted administrators only.
References
- WEB https://github.com/BerriAI/litellm/security/advisories/GHSA-4g5m-c9r5-49xf
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2026-59819
- WEB https://github.com/BerriAI/litellm/pull/25592
- PACKAGE https://github.com/BerriAI/litellm
- WEB https://github.com/BerriAI/litellm/releases/tag/v1.83.10-stable
- PACKAGE https://pypi.org/project/litellm
- ADVISORY https://github.com/advisories/GHSA-4g5m-c9r5-49xf
Ready to move
Start Securing
Free, no credit card | First findings in minutes