PT-2026-105826 · Pypi · Litellm

Published

2026-10-01

·

Updated

2026-10-01

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N

Summary

A server-side request forgery in LiteLLM Proxy lets an authenticated caller redirect the proxy's outbound request to a host of their choosing by smuggling an api base inside the user config request body, bypassing the existing parameter guard.

Details

LiteLLM Proxy validates request bodies with is request body safe, which blocks the api base and base url parameters but does not cover user config. The user config object is used to build the outbound router for a request, so a caller can place an api base inside it and reach an arbitrary host. The guard only inspected the two top-level keys, so the same api base nested inside user config was never checked.
Exploitation requires a valid virtual key.

Impact

An authenticated caller can make the proxy issue server-side requests to internal or external hosts of their choosing, reaching endpoints the caller cannot otherwise access.

Affected / Patched

Affected: <= 1.83.8 Patched: 1.83.9

Remediation

Upgrade to 1.83.9 or later (released 2026-04-17).

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

PYSEC-2026-4070

Affected Products

Litellm