LiteLLM: Local file read via request-supplied OIDC file references
LiteLLM: Local file read via request-supplied OIDC file references
Low severity. Affects litellm < 1.83.10. Upgrade to 1.83.10 or later.
CVE-2026-59819 / GHSA-4g5m-c9r5-49xf · severity: low · PyPI
Affected
litellm< 1.83.10 → fixed in 1.83.10
Details
Impact
LiteLLM's /health/test_connection endpoint resolved request-supplied environment and OIDC file references in litellm_params. A proxy administrator, or another privileged caller with permission to test model connections, could cause LiteLLM to read files from the local filesystem via an oidc/file/ reference.
Because exploitation requires privileged proxy access, this is treated as a defense-in-depth issue rather than a cross-tenant privilege bypass.
Patches
The issue is fixed in 1.83.10-stable.
LiteLLM recommend upgrading to 1.83.10-stable or later.
Workarounds
Restrict /health/test_connection access to trusted administrators only.
Source: GHSA-4g5m-c9r5-49xf — GitHub Advisory Database (CC-BY-4.0).