AUGUST 24, 2026
Live Feed
Back to database
Case File

CVE-2026-59819

MEDIUM · CVSS 4.9 EPSS 0.26% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-08 · Last synced 2026-08-07

CyberRota Analysis

AI-Generated

LiteLLM versions prior to 1.83.10-stable are vulnerable due to improper handling of request-supplied parameters in the /health/test_connection endpoint, which allows privileged users to access local filesystem files through OIDC/file references. This vulnerability could lead to unauthorized information disclosure, potentially exposing sensitive data. Organizations using LiteLLM as a proxy server should prioritize upgrading to the latest version to mitigate this risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-59819
Severity
MEDIUM
CVSS
4.9
EPSS
0.26%

Original NVD Description

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.10-stable, LiteLLM's /health/test_connection endpoint resolved request-supplied environment and OIDC file references in litellm_params, allowing a proxy administrator or another privileged caller with permission to test model connections to read files from the local filesystem via an oidc/file/ reference. This issue is fixed in version 1.83.10-stable.

Related CVEs

Other vulnerabilities affecting the same vendor(s)