Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Yuneng-Berri

Researcher fromBerriAI
#43559of 56,330
6.5Total CVSS
Vulnerabilities · 1
PT-2026-56543
6.5
2026-07-08
Litellm · Litellm · CVE-2026-59820
**Name of the Vulnerable Software and Affected Versions** LiteLLM versions prior to 1.83.7-stable **Description** LiteLLM, a proxy server used to call LLM APIs, contains a flaw in its Skills archive extraction process. An authenticated user with access to the LLM API routes or a key permitted to use `/v1/skills`, `anthropic routes`, or `llm api routes` can upload a specially crafted ZIP archive. This archive can contain path traversal entries, which allow files to be written outside the intended extraction or staging directory. Path traversal is a technique used to access files and directories that are stored outside the web root folder. This issue has been exploited in real-world incidents. **Recommendations** Update to version 1.83.7-stable.