PT-2026-64086 · Pypi · Litellm
Publicado
2026-07-23
·
Atualizado
2026-07-23
CVSS v4.0
2.1
Baixa
| Vetor | AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N |
Impact
LiteLLM's
/health/test connection endpoint resolved request-supplied environment and OIDC file references in litellm params. A proxy administrator, or another privileged caller with permission to test model connections, could cause LiteLLM to read files from the local filesystem via an oidc/file/ reference.Because exploitation requires privileged proxy access, this is treated as a defense-in-depth issue rather than a cross-tenant privilege bypass.
Patches
The issue is fixed in
1.83.10-stable.LiteLLM recommend upgrading to
1.83.10-stable or later.Workarounds
Restrict
/health/test connection access to trusted administrators only.Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Litellm