A AegiFlow
LOWCVSS 2.1EPSS 0.3%

CVE-2026-59819

LiteLLM: Local file read via request-supplied OIDC file references

Published
2026-07-22
Modified
2026-07-22
EPSS percentile
17%
Aliases
GHSA-4g5m-c9r5-49xf
Sources
github-advisory

Summary

### Impact LiteLLM's `/health/test_connection` endpoint resolved request-supplied environment and OIDC file references in `litellm_params`. A proxy administrator, or another privileged caller with permission to test model connections, could cause LiteLLM to read files from the local filesystem via an `oidc/file/` reference. Because exploitation requires privileged proxy access, this is treated as a defense-in-depth issue rather than a cross-tenant privilege bypass. ### Patches The issue is fixed in `1.83.10-stable`. LiteLLM recommend upgrading to `1.83.10-stable` or later. ### Workarounds Restrict `/health/test_connection` access to trusted administrators only.

Affected packages

EcosystemPackageAffected versionsFixed versions
PyPIlitellm1.83.10

Remediation: Upgrade to 1.83.10 or later.

References

Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.

EPSS scores provided by the FIRST.org Exploit Prediction Scoring System.