Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-35029

Опубликовано: 06 апр. 2026
Источник: redhat
CVSS3: 8.8
EPSS Средний

Описание

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.0, the /config/update endpoint does not enforce admin role authorization. A user who is already authenticated into the platform can then use this endpoint to modify proxy configuration and environment variables, register custom pass-through endpoint handlers pointing to attacker-controlled Python code, achieving remote code execution, read arbitrary server files by setting UI_LOGO_PATH and fetching via /get_image, and take over other privileged accounts by overwriting UI_USERNAME and UI_PASSWORD environment variables. Fixed in v1.83.0.

A flaw was found in LiteLLM, an AI Gateway proxy server. An authenticated user can exploit a missing authorization check on the /config/update endpoint. This allows the user to modify proxy configurations and environment variables, leading to remote code execution by registering custom endpoint handlers. Additionally, this vulnerability enables unauthorized reading of server files and potential takeover of privileged accounts through environment variable manipulation.

Отчет

This Important flaw in LiteLLM allows an authenticated user to bypass authorization on the /config/update endpoint. This enables modification of proxy configurations and environment variables, leading to remote code execution, unauthorized file access, and potential account takeover. Red Hat Ansible Automation Platform, Lightspeed Core, and Red Hat OpenShift AI are affected.

Меры по смягчению последствий

Limit network access to the LiteLLM service to trusted networks or hosts only. Implement firewall rules to restrict inbound connections to the LiteLLM service's port, ensuring that only authorized systems can reach the service. This reduces the exposure of the /config/update endpoint to unauthorized authenticated users.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Lightspeed Coreredhat-user-workloads/lightspeed-stackAffected
Red Hat OpenShift AI (RHOAI)rhoai/odh-mlflow-rhel9Not affected
Red Hat Ansible Automation Platform 2.6ansible-automation-platform-26/lightspeed-chatbot-rhel9FixedRHSA-2026:1354504.05.2026
Red Hat OpenShift AI 2.25rhoai/odh-llama-stack-core-rhel9FixedRHSA-2026:2896024.06.2026
Red Hat OpenShift AI 3.3rhoai/odh-llama-stack-core-rhel9FixedRHSA-2026:3005625.06.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-425
https://bugzilla.redhat.com/show_bug.cgi?id=2455474litellm: LiteLLM: Remote code execution and privilege escalation via unrestricted proxy configuration endpoint

EPSS

Процентиль: 98%
0.26409
Средний

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
nvd
4 месяца назад

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.0, the /config/update endpoint does not enforce admin role authorization. A user who is already authenticated into the platform can then use this endpoint to modify proxy configuration and environment variables, register custom pass-through endpoint handlers pointing to attacker-controlled Python code, achieving remote code execution, read arbitrary server files by setting UI_LOGO_PATH and fetching via /get_image, and take over other privileged accounts by overwriting UI_USERNAME and UI_PASSWORD environment variables. Fixed in v1.83.0.

github
4 месяца назад

LiteLLM: Privilege escalation via unrestricted proxy configuration endpoint

EPSS

Процентиль: 98%
0.26409
Средний

8.8 High

CVSS3