Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-59820

Опубликовано: 08 июл. 2026
Источник: redhat
CVSS3: 8.1
EPSS Низкий

Описание

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.7-stable, LiteLLM Skills archive extraction did not sufficiently validate file paths from uploaded skill ZIP archives, allowing an authenticated user with access to LiteLLM LLM API routes or a key whose allowed_routes includes /v1/skills, anthropic_routes, or llm_api_routes to upload a crafted skill archive containing path traversal entries that could be written outside the intended extraction or staging directory. This issue is fixed in version 1.83.7-stable.

A flaw was found in LiteLLM, a proxy server for Large Language Model (LLM) APIs. An authenticated user, with specific API route access, could upload a specially crafted skill archive. This archive, containing path traversal entries, would allow files to be written outside of the designated extraction directory. This vulnerability could lead to arbitrary file creation or modification, potentially resulting in system compromise.

Отчет

LiteLLM prior to 1.83.7-stable does not sufficiently validate file paths extracted from uploaded Skills ZIP archives, allowing path traversal writes outside the intended extraction directory. Exploitation requires the LiteLLM Proxy Server's Skills API (/v1/skills, anthropic_routes, or llm_api_routes) to be enabled and reachable by an authenticated caller. Fixed in 1.83.7-stable.

Меры по смягчению последствий

Upgrade to LiteLLM 1.83.7-stable or later. Products that use LiteLLM only as a Python SDK (litellm.completion()) rather than running the LiteLLM Proxy Server with the Skills feature enabled are not exposed to this vulnerability, as the vulnerable HTTP upload endpoint does not exist in SDK-only usage.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Exploit Intelligenceexploit-intelligence-tech-preview/vulnerability-analysis-rhel9Affected
Lightspeed Corelightspeed-core/lightspeed-stack-rhel9Not affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-26/lightspeed-chatbot-rhel9Not affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-27/lightspeed-chatbot-rhel9Not affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-llama-stack-core-rhel9Not affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-mlflow-rhel9Not affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-trustyai-garak-lls-provider-dsp-rhel9Not affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-22
https://bugzilla.redhat.com/show_bug.cgi?id=2498198litellm: LiteLLM: Directory traversal via crafted skill archive upload

EPSS

Процентиль: 24%
0.00313
Низкий

8.1 High

CVSS3

Связанные уязвимости

CVSS3: 6.5
nvd
26 дней назад

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.7-stable, LiteLLM Skills archive extraction did not sufficiently validate file paths from uploaded skill ZIP archives, allowing an authenticated user with access to LiteLLM LLM API routes or a key whose allowed_routes includes /v1/skills, anthropic_routes, or llm_api_routes to upload a crafted skill archive containing path traversal entries that could be written outside the intended extraction or staging directory. This issue is fixed in version 1.83.7-stable.

github
12 дней назад

LiteLLM: Arbitrary file write via path traversal in Skills archive extraction

EPSS

Процентиль: 24%
0.00313
Низкий

8.1 High

CVSS3