LiteLLM: Arbitrary file write via path traversal in Skills archive extraction
PYSEC-2026-3477 · CVE-2026-59820 · GHSA-5jmr-gcrj-2c9q
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
Impact
LiteLLM Skills archive extraction did not sufficiently validate file paths from uploaded skill ZIP archives. An authenticated user with access to LiteLLM LLM API routes, or a key whose allowed_routes includes /v1/skills, anthropic_routes, or llm_api_routes, could upload a crafted skill archive containing path traversal entries.
When the skill was processed for execution, those entries could be written outside the intended extraction/staging directory. This could allow arbitrary file write and may lead to code execution depending on deployment configuration and writable paths.
Patches
The issue is fixed in 1.83.7-stable.
LiteLLM recommens upgrading to 1.83.7-stable or later.
Workarounds
If upgrading is not immediately possible:
- Block
POST /v1/skillsat your reverse proxy or API gateway. - Restrict Skills API access to trusted users only.
References
- WEB https://github.com/BerriAI/litellm/security/advisories/GHSA-5jmr-gcrj-2c9q
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2026-59820
- WEB https://github.com/BerriAI/litellm/pull/25475
- WEB https://github.com/BerriAI/litellm/commit/6a15adcd64137d37f73dee76dfe7481f8c2d9196
- PACKAGE https://github.com/BerriAI/litellm
- WEB https://github.com/BerriAI/litellm/releases/tag/v1.83.7-stable
- PACKAGE https://pypi.org/project/litellm
- ADVISORY https://github.com/advisories/GHSA-5jmr-gcrj-2c9q
Ready to move
Start Securing
Free, no credit card | First findings in minutes