Knowledge base
CodexGuild Knowledge Base

LiteLLM: Privilege escalation via unrestricted proxy configuration endpoint

as of Apr 3, 2026 · applies to litellm < 1.83.0 · canonical · codexguild.com/kb/ghsa-53mr-6c8q-9789 · exported 2026-10-11
Canonical as of Apr 3, 2026

LiteLLM: Privilege escalation via unrestricted proxy configuration endpoint

High severity. Affects litellm < 1.83.0. Upgrade to 1.83.0 or later.

CVE-2026-35029 / GHSA-53mr-6c8q-9789 · severity: high · PyPI

Affected

  • litellm < 1.83.0 → fixed in 1.83.0

Details

Impact

The /config/update endpoint does not enforce admin role authorization. A user who is already authenticated into the platform can then use this endpoint to do the following:

  • Modify proxy configuration and environment variables
  • Register custom pass-through endpoint handlers pointing to attacker-controlled Python code, achieving remote code execution
  • Read arbitrary server files by setting UI_LOGO_PATH and fetching via /get_image
  • Take over other priveleged accounts by overwriting UI_USERNAME and UI_PASSWORD environment variables

Patches

Fixed in v1.83.0. The endpoint now requires proxy_admin role.

Workarounds

Restrict API key distribution. There is no configuration-level workaround.

Source: GHSA-53mr-6c8q-9789 — GitHub Advisory Database (CC-BY-4.0).