CVE-2026-59819: LiteLLM: Local file read via request-supplied OIDC file references

Published Jul 8, 2026
·
Updated

Impact

LiteLLM's /health/testconnection endpoint resolved request-supplied environment and OIDC file references in litellmparams. A proxy administrator, or another privileged caller with permission to test model connections, could cause LiteLLM to read files from the local filesystem via an oidc/file/ reference.

Because exploitation requires privileged proxy access, this is treated as a defense-in-depth issue rather than a cross-tenant privilege bypass.

Patches

The issue is fixed in 1.83.10-stable.

LiteLLM recommend upgrading to 1.83.10-stable or later.

Workarounds

Restrict /health/testconnection access to trusted administrators only.

Other sources

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.10-stable, LiteLLM's /health/testconnection endpoint resolved request-supplied environment and OIDC file references in litellmparams, allowing a proxy administrator or another privileged caller with permission to test model connections to read files from the local filesystem via an oidc/file/ reference. This issue is fixed in version 1.83.10-stable.

MITRE

Affected Software

4 affected componentsFixes available
LiteLLM LiteLLM<1.83.10-stable
LiteLLM LiteLLM<1.83.10
LiteLLM LiteLLM=1.83.10-nightly
pip/litellm<1.83.10
1.83.10

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade pip/litellm to a version that resolves this vulnerability.

    Fixed in 1.83.10
  2. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 1.83.10-stable
  3. Configuration

    Restrict LiteLLM's /health/test_connection endpoint to trusted administrators only to prevent privileged callers from exploiting request-supplied environment and OIDC file references in litellm_params for local file reads via an oidc/file/ reference.

    LiteLLM (proxy server) /health/test_connection endpoint access control = trusted administrators only

Event History

Jul 8, 2026
CVE Published
via MITRE·07:33 PM
Data Sourced
via MITRE·07:33 PM
DescriptionWeakness
Data Sourced
via NVD·08:16 PM
RemedyDescriptionSeverityWeaknessAffected Software
Jul 22, 2026
Advisory Published
via GitHub·10:38 PM
Data Sourced
via GitHub·10:38 PM
DescriptionWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-59819?

The severity of CVE-2026-59819 is low, with a CVSS score of 4.0.

2

What does CVE-2026-59819 allow an attacker to do?

CVE-2026-59819 allows an attacker to read local files via request-supplied OIDC file references in LiteLLM's parameters.

3

How do I fix CVE-2026-59819?

To fix CVE-2026-59819, update LiteLLM to version 1.83.10-stable or later.

4

Which software is affected by CVE-2026-59819?

LiteLLM versions prior to 1.83.10-stable are affected by CVE-2026-59819.

5

When was CVE-2026-59819 published?

CVE-2026-59819 was published on July 8, 2026.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203