LiteLLM是LiteLLM团队开源的一个应用程序。 LiteLLM 1.82.0-stable之前版本存在代码注入漏洞,该漏洞源于对自定义代码防护栏的创建和更新路径未应用与测试端点相同的沙箱和验证机制,可能导致权限高的用户提交自定义Python代码并在LiteLLM代理环境中执行,从而暴露进程可访问的机密信息。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-59822 | 8.8 HIGH | LiteLLM: MCP Authentication Bypass via OAuth2 Passthrough Fallback |
| CVE-2026-59820 | LiteLLM: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | |
| CVE-2026-59819 | LiteLLM: Local file read via request-supplied OIDC file references |
No comments yet