PT-2026-30278 · Litellm · Litellm

Highjaydns

·

Published

2026-04-03

·

Updated

2026-05-07

·

CVE-2026-35029

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions LiteLLM versions prior to 1.83.0
Description LiteLLM is a proxy server for LLM APIs. The /config/update API endpoint did not enforce admin role authorization, allowing authenticated users to modify proxy configurations and environment variables. This could lead to remote code execution by registering custom pass-through endpoint handlers pointing to attacker-controlled Python code, reading arbitrary server files via the /get image endpoint by manipulating the UI LOGO PATH variable, and taking over privileged accounts by overwriting the UI USERNAME and UI PASSWORD environment variables. The endpoint now requires the proxy admin role.
Recommendations Update to version 1.83.0 or later.

Fix

RCE

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-35029
ECHO-F909-9693-1F3F
GHSA-53MR-6C8Q-9789

Affected Products

Litellm