Security Bypass in LiteLLM Proxy Server by BerriAI
CVE-2026-59823
5.3MEDIUM
What is CVE-2026-59823?
LiteLLM, a proxy server for LLM APIs, previously lacked proper input validation for the user_config parameter, allowing authenticated users with a valid virtual key to bypass crucial security checks. This vulnerability enabled attackers to redirect server-side requests to unintended internal or external hosts, exposing sensitive endpoints that should have remained inaccessible. The issue has been addressed in version 1.83.9, which reinforces the importance of thorough input validation in API management.
Affected Version(s)
litellm < 1.83.9
