CVE-2026-59820: LiteLLM: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Published Jul 8, 2026
·
Updated

Impact

LiteLLM Skills archive extraction did not sufficiently validate file paths from uploaded skill ZIP archives. An authenticated user with access to LiteLLM LLM API routes, or a key whose allowedroutes includes /v1/skills, anthropicroutes, or llmapiroutes, could upload a crafted skill archive containing path traversal entries.

When the skill was processed for execution, those entries could be written outside the intended extraction/staging directory. This could allow arbitrary file write and may lead to code execution depending on deployment configuration and writable paths.

Patches

The issue is fixed in 1.83.7-stable.

LiteLLM recommens upgrading to 1.83.7-stable or later.

Workarounds

If upgrading is not immediately possible:

1. Block POST /v1/skills at your reverse proxy or API gateway. 2. Restrict Skills API access to trusted users only.

Other sources

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.7-stable, LiteLLM Skills archive extraction did not sufficiently validate file paths from uploaded skill ZIP archives, allowing an authenticated user with access to LiteLLM LLM API routes or a key whose allowedroutes includes /v1/skills, anthropicroutes, or llmapiroutes to upload a crafted skill archive containing path traversal entries that could be written outside the intended extraction or staging directory. This issue is fixed in version 1.83.7-stable.

MITRE

Affected Software

4 affected componentsFixes available
LiteLLM<1.83.7-stable
LiteLLM LiteLLM<1.83.7
LiteLLM LiteLLM=1.83.7-rc1
pip/litellm<1.83.7
1.83.7

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade pip/litellm to a version that resolves this vulnerability.

    Fixed in 1.83.7
  2. Upgrade

    Upgrade LiteLLM to a version that resolves this vulnerability.

    Fixed in 1.83.7-stable
  3. Configuration

    Restrict Skills API access to trusted users only (so only trusted authenticated users/keys can access the /v1/skills and related route sets).

    LiteLLM Skills API Access control for Skills API routes (e.g., /v1/skills, anthropic_routes, llm_api_routes) = trusted-only
  4. Compensating control

    Block POST /v1/skills at your reverse proxy or API gateway.

Event History

Jul 8, 2026
CVE Published
via MITRE·07:32 PM
Data Sourced
via MITRE·07:32 PM
DescriptionWeakness
Data Sourced
via NVD·08:16 PM
RemedyDescriptionSeverityWeaknessAffected Software
Jul 22, 2026
Advisory Published
via GitHub·10:37 PM
Data Sourced
via GitHub·10:37 PM
DescriptionWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-59820?

The severity of CVE-2026-59820 is medium with a CVSS score of 6.1.

2

How do I fix CVE-2026-59820?

To fix CVE-2026-59820, upgrade LiteLLM to version 1.83.7-stable or later.

3

What type of vulnerability is CVE-2026-59820?

CVE-2026-59820 is classified as a Path Traversal vulnerability.

4

Who is affected by CVE-2026-59820?

Authenticated users with access to LiteLLM LLM API routes or a key are affected by CVE-2026-59820.

5

Can CVE-2026-59820 be exploited remotely?

Yes, CVE-2026-59820 can potentially be exploited by remote authenticated users.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203