CVE-2026-59819
LiteLLM: Local file read via request-supplied OIDC file references
Summary
### Impact LiteLLM's `/health/test_connection` endpoint resolved request-supplied environment and OIDC file references in `litellm_params`. A proxy administrator, or another privileged caller with permission to test model connections, could cause LiteLLM to read files from the local filesystem via an `oidc/file/` reference. Because exploitation requires privileged proxy access, this is treated as a defense-in-depth issue rather than a cross-tenant privilege bypass. ### Patches The issue is fixed in `1.83.10-stable`. LiteLLM recommend upgrading to `1.83.10-stable` or later. ### Workarounds Restrict `/health/test_connection` access to trusted administrators only.
Affected packages
| Ecosystem | Package | Affected versions | Fixed versions |
|---|---|---|---|
| PyPI | litellm | — | 1.83.10 |
Remediation: Upgrade to 1.83.10 or later.
References
Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.
CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.
EPSS scores provided by the FIRST.org Exploit Prediction Scoring System.