Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-59820

Опубликовано: 08 июл. 2026
Источник: nvd
CVSS3: 6.5
EPSS Низкий

Описание

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.7-stable, LiteLLM Skills archive extraction did not sufficiently validate file paths from uploaded skill ZIP archives, allowing an authenticated user with access to LiteLLM LLM API routes or a key whose allowed_routes includes /v1/skills, anthropic_routes, or llm_api_routes to upload a crafted skill archive containing path traversal entries that could be written outside the intended extraction or staging directory. This issue is fixed in version 1.83.7-stable.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:litellm:litellm:*:*:*:*:*:*:*:*
Версия до 1.83.7 (исключая)
cpe:2.3:a:litellm:litellm:1.83.7:rc1:*:*:*:*:*:*

EPSS

Процентиль: 24%
0.00313
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 8.1
redhat
26 дней назад

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.7-stable, LiteLLM Skills archive extraction did not sufficiently validate file paths from uploaded skill ZIP archives, allowing an authenticated user with access to LiteLLM LLM API routes or a key whose allowed_routes includes /v1/skills, anthropic_routes, or llm_api_routes to upload a crafted skill archive containing path traversal entries that could be written outside the intended extraction or staging directory. This issue is fixed in version 1.83.7-stable.

github
12 дней назад

LiteLLM: Arbitrary file write via path traversal in Skills archive extraction

EPSS

Процентиль: 24%
0.00313
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-22