Zurück zur CVE-Übersicht
CVE-2026-59819
MEDIUM(4.9)CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Risk Signal Score12/100 — NIEDRIG
- CVSS 4.9 — Mittel
Erwähnungen (letzte 60 Tage)
Artikel
EPSS-Score
0.6%
Exploit-Wahrscheinlichkeit (30 Tage)
CVSS Score
4.9
Technische Schwere
Beschreibung
LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.10-stable, LiteLLM's /health/test_connection endpoint resolved request-supplied environment and OIDC file references in litellm_params, allowing a proxy administrator or another privileged caller with permission to test model connections to read files from the local filesystem via an oidc/file/ reference. This issue is fixed in version 1.83.10-stable.
GitHub Advisories
GHSA-4g5m-c9r5-49xfLOW
LiteLLM: Local file read via request-supplied OIDC file references
pip/litellm→ 1.83.10
GitHub Advisory