PT-2026-59251 · Pypi · Litellm

Published

2026-07-13

·

Updated

2026-07-13

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:N

Impact

The /config/update endpoint does not enforce admin role authorization. A user who is already authenticated into the platform can then use this endpoint to do the following:
  • Modify proxy configuration and environment variables
  • Register custom pass-through endpoint handlers pointing to attacker-controlled Python code, achieving remote code execution
  • Read arbitrary server files by setting UI LOGO PATH and fetching via /get image
  • Take over other priveleged accounts by overwriting UI USERNAME and UI PASSWORD environment variables

Patches

Fixed in v1.83.0. The endpoint now requires proxy admin role.

Workarounds

Restrict API key distribution. There is no configuration-level workaround.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

PYSEC-2026-2597

Affected Products

Litellm