Knowledge base
CodexGuild Knowledge Base

LiteLLM: Local file read via request-supplied OIDC file references

as of Jul 22, 2026 · applies to litellm < 1.83.10 · canonical · codexguild.com/kb/ghsa-4g5m-c9r5-49xf · exported 2026-10-11
Canonical as of Jul 22, 2026

LiteLLM: Local file read via request-supplied OIDC file references

Low severity. Affects litellm < 1.83.10. Upgrade to 1.83.10 or later.

CVE-2026-59819 / GHSA-4g5m-c9r5-49xf · severity: low · PyPI

Affected

  • litellm < 1.83.10 → fixed in 1.83.10

Details

Impact

LiteLLM's /health/test_connection endpoint resolved request-supplied environment and OIDC file references in litellm_params. A proxy administrator, or another privileged caller with permission to test model connections, could cause LiteLLM to read files from the local filesystem via an oidc/file/ reference.

Because exploitation requires privileged proxy access, this is treated as a defense-in-depth issue rather than a cross-tenant privilege bypass.

Patches

The issue is fixed in 1.83.10-stable.

LiteLLM recommend upgrading to 1.83.10-stable or later.

Workarounds

Restrict /health/test_connection access to trusted administrators only.

Source: GHSA-4g5m-c9r5-49xf — GitHub Advisory Database (CC-BY-4.0).