Path Traversal Vulnerability in LiteLLM by BerriAI
CVE-2026-59820
6.1MEDIUM
What is CVE-2026-59820?
LiteLLM, a proxy server designed for seamless interaction with LLM APIs, faced a significant security issue prior to version 1.83.7-stable. This vulnerability stemmed from inadequate validation of file paths when extracting archives from uploaded skill ZIP files. An authenticated user with access to specific LiteLLM API routes could exploit this flaw by uploading a specially crafted skill archive containing path traversal entries. Such entries enabled the potential for files to be extracted outside of the designated directories, posing a risk to the integrity of the system. BerriAI has addressed this vulnerability in the latest stable release.
Affected Version(s)
litellm < 1.83.7-stable
