LiteLLM: Arbitrary file write via path traversal in Skills archive extraction
LiteLLM: Arbitrary file write via path traversal in Skills archive extraction
Medium severity. Affects litellm < 1.83.7. Upgrade to 1.83.7 or later.
CVE-2026-59820 / GHSA-5jmr-gcrj-2c9q · severity: medium · PyPI
Affected
litellm< 1.83.7 → fixed in 1.83.7
Details
Impact
LiteLLM Skills archive extraction did not sufficiently validate file paths from uploaded skill ZIP archives. An authenticated user with access to LiteLLM LLM API routes, or a key whose allowed_routes includes /v1/skills, anthropic_routes, or llm_api_routes, could upload a crafted skill archive containing path traversal entries.
When the skill was processed for execution, those entries could be written outside the intended extraction/staging directory. This could allow arbitrary file write and may lead to code execution depending on deployment configuration and writable paths.
Patches
The issue is fixed in 1.83.7-stable.
LiteLLM recommens upgrading to 1.83.7-stable or later.
Workarounds
If upgrading is not immediately possible:
- Block
POST /v1/skillsat your reverse proxy or API gateway. - Restrict Skills API access to trusted users only.
Source: GHSA-5jmr-gcrj-2c9q — GitHub Advisory Database (CC-BY-4.0).