PT-2026-59251 · Pypi · Litellm

Publicado

2026-07-13

·

Atualizado

2026-07-13

CVSS v4.0

8.7

Alta

VetorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:N

Impact

The /config/update endpoint does not enforce admin role authorization. A user who is already authenticated into the platform can then use this endpoint to do the following:
  • Modify proxy configuration and environment variables
  • Register custom pass-through endpoint handlers pointing to attacker-controlled Python code, achieving remote code execution
  • Read arbitrary server files by setting UI LOGO PATH and fetching via /get image
  • Take over other priveleged accounts by overwriting UI USERNAME and UI PASSWORD environment variables

Patches

Fixed in v1.83.0. The endpoint now requires proxy admin role.

Workarounds

Restrict API key distribution. There is no configuration-level workaround.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

PYSEC-2026-2597

Produtos afetados

Litellm