A AegiFlow
MEDIUMCVSS 6.1EPSS 0.3%

CVE-2026-59820

LiteLLM: Arbitrary file write via path traversal in Skills archive extraction

Published
2026-07-22
Modified
2026-07-22
EPSS percentile
24%
Aliases
GHSA-5jmr-gcrj-2c9q
Sources
github-advisory

Summary

### Impact LiteLLM Skills archive extraction did not sufficiently validate file paths from uploaded skill ZIP archives. An authenticated user with access to LiteLLM LLM API routes, or a key whose `allowed_routes` includes `/v1/skills`, `anthropic_routes`, or `llm_api_routes`, could upload a crafted skill archive containing path traversal entries. When the skill was processed for execution, those entries could be written outside the intended extraction/staging directory. This could allow arbitrary file write and may lead to code execution depending on deployment configuration and writable paths. ### Patches The issue is fixed in `1.83.7-stable`. LiteLLM recommens upgrading to `1.83.7-stable` or later. ### Workarounds If upgrading is not immediately possible: 1. Block `POST /v1/skills` at your reverse proxy or API gateway. 2. Restrict Skills API access to trusted users only.

Affected packages

EcosystemPackageAffected versionsFixed versions
PyPIlitellm1.83.7

Remediation: Upgrade to 1.83.7 or later.

References

Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.

EPSS scores provided by the FIRST.org Exploit Prediction Scoring System.