CVE-2026-59821Active Exploitation(litellm / litellm)

HIGHCVSS 7.2 · HIGH

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch litellm litellm systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts

Recommended action window: Immediate (within 24h)

NVD description

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.82.0-stable, LiteLLM's Custom Code Guardrails production create and update paths did not apply the same sandboxing and validation used by the test endpoint, allowing a privileged user with access to create or update guardrails to submit custom Python code that executed in the LiteLLM proxy environment and could expose secrets available to the process. This issue is fixed in version 1.82.0-stable.

6.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

HIGH

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • litellm

Threat summary

  • Active exploitation appears in 2 classified signals
  • Exploit tooling references are present in monitored signal
  • Patch or workaround signal is available
  • 3 mentions across 3 observed days

What's happening

  • Active exploitation reported across 2 signals
  • Exploit tool or code specified in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-07-08); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
litellm

1 version affected across 1 product

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-07-08: 1Mentions · 2026-09-09: 1Mentions · 2026-09-10: 1Exploit Tool / Code · 2026-09-09: 1Active Exploitation · 2026-07-08: 1Active Exploitation · 2026-09-09: 1Patch / Workaround · 2026-09-09: 1Technical Details · 2026-09-09: 1Technical Details · 2026-09-10: 107-0809-0909-10
Signal classification2 categories
Active Exploitation
266.7%
Disclosure
133.3%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-07-081
Active Exploitation1
2026-09-091
Active Exploitation1
2026-09-101
Disclosure1
Full discourse3 posts
  • DFIR Radar@DFIR_Radar
    Active Exploitation

    LiteLLM auth bypass chains to root-level RCE and IAM credential theft. CVE-2026-59822 is actively exploited in the wild and now on CISA KEV, present in roughly one-third of cloud environments. Key findings: - CVE-2026-59822 (MCP auth bypass): the MCP auth handler in user_api_key_auth_mcp.py catches 401s from invalid tokens and returns an empty UserAPIKeyAuth() object, granting a fully authenticated session. A single request with "Authorization: Bearer a" is enough. Honeypot data confirmed active exploitation as of 2026-07-07. Fix landed in v1.84.0. - CVE-2026-59821 (post-auth RCE): the guardrail registration endpoint (POST /guardrails) called exec(compile(...)) without stripping __builtins__ or running the forbidden-patterns check, giving submitted Python the full standard library. Code executed at registration time, not inference time. Fixed in v1.82.0 with sandbox enforcement and PROXY_ADMIN gating. - 9.6% of 3,074 scanned public instances accepted the default master key (sk-1234) or required no auth. Pre-patch, no-auth deployments granted PROXY_ADMIN to every request by default. Chaining default key plus CVE-2026-59821 (pre-v1.82.0) yields pre-auth root in one request. - Pass-through endpoints proxy requests to arbitrary URLs with no validation, including AWS IMDS. The x-pass- header prefix strips and forwards headers to the target, defeating IMDSv2 protections and enabling IAM credential exfiltration post-auth. #DFIR_Radar

    Post summary

    The piece reports that CVE-2026-59822 is being actively exploited, provides detailed exploitation steps for auth bypass and RCE, and notes patches that have been released.

    30000196
    1.9K followersView on X
  • Shogo Katsurada@shogokatsurada
    Disclosure

    攻撃面は3つ。 ① MCP認証バイパス(CVE-2026-59822) Authorization: Bearer a だけでセッション確立。 接続先MCP(DB / GitHub / 社内ツール)を叩ける。 ② Guardrailの custom code が登録時に exec() サンドボックスがテスト用エンドポイントにしか無く、rootでコード実行(CVE-2026-59821)。 ③ パススルーにURL検証なし 169.254.169.254 を向けてIMDSからIAMを抜ける。IMDSv2もヘッダ転送で回避。

    Post summary

    The passage enumerates three CVE-related attack surfaces, offering technical details of each vulnerability’s exploitation path while lacking explicit PoC links, active exploitation claims, or patch information.

    10000160
    834 followersView on X
  • Kaitan ID Security@KaitanSecurity
    Active Exploitation

    ⚠️ HIGH — CVE-2026-59821 LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.82.0-stable, LiteLLM's… CVSS 2.1 ⚡ Exploit in the wild Full analysis → https://sec.kaitan.id/cves/CVE-2026-59821 #OpenAI #CyberSecurity #InfoSec

    Post summary

    CVE-2026-59821 is being actively exploited in the wild against LiteLLM versions earlier than 1.82.0; no patch or detailed exploit description is provided in the snippet.

    0000077
    84 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Applitellmlitellm---
Applitellmlitellm1.82.0--

Explore more