CVE-2026-59820Active Exploitation(litellm / litellm)

LOWCVSS 6.5 · MEDIUM

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for litellm litellm systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.7-stable, LiteLLM Skills archive extraction did not sufficiently validate file paths from uploaded skill ZIP archives, allowing an authenticated user with access to LiteLLM LLM API routes or a key whose allowed_routes includes /v1/skills, anthropic_routes, or llm_api_routes to upload a crafted skill archive containing path traversal entries that could be written outside the intended extraction or staging directory. This issue is fixed in version 1.83.7-stable.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • litellm

Threat summary

  • Active exploitation appears in 1 classified signals
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-07-08); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
litellm

1 version affected across 1 product

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-07-08: 1Mentions · 2026-07-13: 1Active Exploitation · 2026-07-08: 1Technical Details · 2026-07-08: 1Technical Details · 2026-07-13: 107-0807-13
Signal classification2 categories
Active Exploitation
150.0%
Disclosure
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-07-081
Active Exploitation1
2026-07-131
Disclosure1
Full discourse2 posts
  • DailyCVE@dailycve
    Disclosure

    🟠 LiteLLM, Path Traversal, #CVE-2026-59820 (Medium) -DC-Jul2026-911 https://dailycve.com/litellm-path-traversal-cve-2026-59820-medium-dc-jul2026-911/

    Post summary

    The content announces a new Medium‑severity Path Traversal vulnerability in LiteLLM (CVE‑2026‑59820) without providing PoC, exploit code, or mitigation details.

    0000049
    218 followersView on X
  • Kaitan ID Security@KaitanSecurity
    Active Exploitation

    ⚠️ HIGH — CVE-2026-59820 LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.7-stable, LiteLLM S… CVSS 6.1 ⚡ Exploit in the wild Full analysis → https://sec.kaitan.id/cves/CVE-2026-59820 #OpenAI #CyberSecurity #InfoSec

    Post summary

    CVE‑2026‑59820, affecting LiteLLM, has a CVSS score of 6.1 and is reported as ‘Exploit in the wild’, with a full analysis available at the provided link.

    0000056
    84 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Applitellmlitellm---
Applitellmlitellm1.83.7--

Explore more