LiteLLM是LiteLLM团队开源的一个应用程序。 LiteLLM 1.83.7-stable之前版本存在路径遍历漏洞,该漏洞源于对上传的技能ZIP存档中文件路径验证不充分,可能导致经过身份验证的用户上传包含路径遍历条目的特制技能存档,从而将文件写入预期提取或暂存目录之外。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-59822 | 8.8 HIGH | LiteLLM: MCP Authentication Bypass via OAuth2 Passthrough Fallback |
| CVE-2026-59821 | LiteLLM: Custom Code Guardrails production endpoints bypass code safety checks | |
| CVE-2026-59819 | LiteLLM: Local file read via request-supplied OIDC file references |
No comments yet