Description
LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.0, the /config/update endpoint does not enforce admin role authorization. A user who is already authenticated into the platform can then use this endpoint to modify proxy configuration and environment variables, register custom pass-through endpoint handlers pointing to attacker-controlled Python code, achieving remote code execution, read arbitrary server files by setting UI_LOGO_PATH and fetching via /get_image, and take over other privileged accounts by overwriting UI_USERNAME and UI_PASSWORD environment variables. Fixed in v1.83.0.
Published: 2026-04-06
Score: 8.7 High
EPSS: 4.0% Low
KEV: No
Impact: Remote Code Execution via Unrestricted Proxy Configuration
Action: Immediate Patch
AI Analysis

Impact

LiteLLM contains a /config/update endpoint that accepts changes without checking whether the caller holds administrative privileges. This lack of authorization enforcement is a CWE‑425 weakness and allows an authenticated user to alter proxy settings, override environment variables, and register custom pass‑through handlers pointing to attacker‑controlled Python code. Such manipulation can trigger remote code execution, enable reading of arbitrary server files by setting UI_LOGO_PATH and retrieving the image, and facilitate credential take‑over by changing UI_USERNAME and UI_PASSWORD. The vulnerability is therefore a high‑severity flaw that exposes the entire LiteLLM instance to compromise once authentication is achieved.

Affected Systems

The vendor BerriAI provides LiteLLM, and all deployments of LiteLLM older than version 1.83.0 that expose the /config/update endpoint are vulnerable. No additional vendors or downstream distributions are listed, so the impact is confined to the primary product and its legacy versions.

Risk and Exploitability

The CVSS score of 8.7 indicates high severity, and the EPSS score of 4% signals a significant likelihood that attackers will exploit the flaw in the wild. The vulnerability is not listed in the CISA KEV catalog, suggesting it has not yet been observed in large‑scale exploitation, but its high probability and the severity of potential impact warrant immediate attention. An attacker must already be authenticated to the system, which could be achieved through legitimate use or credential compromise. Once authenticated, the attacker can issue the vulnerable request from any network location having access to LiteLLM, making the attack vector effectively remote and contingent only on prior access. The conditions for exploitation are minimal—authentication and endpoint reachability—making this a highly actionable threat.

Generated by OpenCVE AI on September 26, 2026 at 08:24 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the official LiteLLM update to version 1.83.0 or newer.
  • Restrict access to the /config/update endpoint so that only users with an administrator role can invoke it, ensuring proper role checks are enforced.
  • Review, sanitize, and hard‑enforce constraints on environment variables that can be configured through the endpoint, especially UI_LOGO_PATH, UI_USERNAME, and UI_PASSWORD.

Generated by OpenCVE AI on September 26, 2026 at 08:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-53mr-6c8q-9789 LiteLLM: Privilege escalation via unrestricted proxy configuration endpoint
History

Wed, 29 Apr 2026 20:30:00 +0000

Type Values Removed Values Added
References

Wed, 08 Apr 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-425
References
Metrics threat_severity

None

threat_severity

Important


Tue, 07 Apr 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Litellm
Litellm litellm
CPEs cpe:2.3:a:litellm:litellm:*:*:*:*:*:*:*:*
Vendors & Products Litellm
Litellm litellm
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Tue, 07 Apr 2026 00:00:00 +0000

Type Values Removed Values Added
First Time appeared Berriai
Berriai litellm
Vendors & Products Berriai
Berriai litellm

Mon, 06 Apr 2026 20:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 06 Apr 2026 18:00:00 +0000

Type Values Removed Values Added
Description LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.0, he /config/update endpoint does not enforce admin role authorization. A user who is already authenticated into the platform can then use this endpoint to modify proxy configuration and environment variables, register custom pass-through endpoint handlers pointing to attacker-controlled Python code, achieving remote code execution, read arbitrary server files by setting UI_LOGO_PATH and fetching via /get_image, and take over other privileged accounts by overwriting UI_USERNAME and UI_PASSWORD environment variables. Fixed in v1.83.0. LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.0, the /config/update endpoint does not enforce admin role authorization. A user who is already authenticated into the platform can then use this endpoint to modify proxy configuration and environment variables, register custom pass-through endpoint handlers pointing to attacker-controlled Python code, achieving remote code execution, read arbitrary server files by setting UI_LOGO_PATH and fetching via /get_image, and take over other privileged accounts by overwriting UI_USERNAME and UI_PASSWORD environment variables. Fixed in v1.83.0.

Mon, 06 Apr 2026 16:45:00 +0000

Type Values Removed Values Added
Description LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.0, he /config/update endpoint does not enforce admin role authorization. A user who is already authenticated into the platform can then use this endpoint to modify proxy configuration and environment variables, register custom pass-through endpoint handlers pointing to attacker-controlled Python code, achieving remote code execution, read arbitrary server files by setting UI_LOGO_PATH and fetching via /get_image, and take over other privileged accounts by overwriting UI_USERNAME and UI_PASSWORD environment variables. Fixed in v1.83.0.
Title LiteLLM affected by privilege escalation via unrestricted proxy configuration endpoint
Weaknesses CWE-863
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-07-15T01:03:19.828Z

Reserved: 2026-03-31T21:06:06.427Z

Link: CVE-2026-35029

cve-icon Vulnrichment

Updated: 2026-04-29T19:32:18.471Z

cve-icon NVD

Status : Modified

Published: 2026-04-06T17:17:12.353

Modified: 2026-07-15T02:20:40.183

Link: CVE-2026-35029

cve-icon Redhat

Severity : Important

Publid Date: 2026-04-06T16:35:28Z

Links: CVE-2026-35029 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-26T08:30:02Z

Weaknesses
  • CWE-425

    Direct Request ('Forced Browsing')

  • CWE-863

    Incorrect Authorization