LiteLLM是LiteLLM团队开源的一个应用程序。 LiteLLM 1.84.0之前版本存在授权问题漏洞,该漏洞源于MCP Streamable HTTP端点允许未经身份验证的攻击者使用伪造的Authorization标头触发OAuth2直通回退路径,导致LiteLLM密钥验证失败并返回空的UserAPIKeyAuth()对象,从而允许无有效密钥的请求访问MCP工具。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-59820 | LiteLLM: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | |
| CVE-2026-59821 | LiteLLM: Custom Code Guardrails production endpoints bypass code safety checks | |
| CVE-2026-59819 | LiteLLM: Local file read via request-supplied OIDC file references |
No comments yet