File Read Vulnerability in LiteLLM Proxy Server by BerriAI
CVE-2026-59819

2.1LOW

Key Information:

Vendor

Berriai

Status
Vendor
CVE Published:
8 July 2026

What is CVE-2026-59819?

LiteLLM, a proxy server facilitating connections to LLM APIs, contains a significant security weakness that allows privileged users to access files on the local filesystem through improperly managed request-supplied environment and OIDC file references in the /health/test_connection endpoint. This flaw, which affects all versions prior to 1.83.10-stable, underscores the importance of timely updates to ensure robust system security and mitigate unauthorized data exposure.

Affected Version(s)

litellm < 1.83.10-stable

References

CVSS V4

Score:
2.1
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.