Executive brief
LiteLLM is an AI gateway used to manage and proxy requests to various Large Language Model (LLM) providers. A security flaw allows any authenticated user to access administrative configuration settings that should be restricted. An attacker could exploit this to steal sensitive credentials, read private server files, or execute malicious code, potentially leading to a full takeover of the AI infrastructure.
Technical details
A broken access control vulnerability exists in the `/config/update` endpoint of LiteLLM due to a missing authorization check for the 'proxy_admin' role. An authenticated attacker with low-level privileges can send a request to this endpoint to modify proxy configurations and environment variables. This can be leveraged to register custom pass-through endpoint handlers pointing to attacker-controlled Python code for Remote Code Execution (RCE). Additionally, attackers can exfiltrate sensitive environment variables (like DATABASE_URL) or read arbitrary system files (such as /etc/passwd) by manipulating the UI_LOGO_PATH and using the /get_image endpoint. The vulnerability is fixed in version 1.83.0.
Affected products
- BerriAI litellm < 1.83.0
- Red Hat Red Hat Ansible Automation Platform 2.6 affected
- Red Hat Red Hat OpenShift AI 2.25 affected
- Red Hat Red Hat OpenShift AI 3.3 affected
- Red Hat Lightspeed Core affected
Timeline
- 2026-02-24: other: Vulnerability discovered by SEC Consult
- 2026-04-01: patched: Security patch released in nightly build
- 2026-04-03: advisory: GitHub security advisory published
- 2026-04-06: disclosed: NVD publication date
- 2026-04-21: other: Coordinated release of SEC Consult advisory
References
- https://github.com/BerriAI/litellm/security/advisories/GHSA-53mr-6c8q-9789
- http://seclists.org/fulldisclosure/2026/Apr/17
- https://access.redhat.com/errata/RHSA-2026:13545
- https://access.redhat.com/errata/RHSA-2026:28960
- https://access.redhat.com/errata/RHSA-2026:30056
- https://access.redhat.com/security/cve/CVE-2026-35029
- https://bugzilla.redhat.com/show_bug.cgi?id=2455474