GHSA-3cv6-jpf6-8222MediumCVSS 6.5

LiteLLM: Authenticated SSRF and provider-credential exfiltration via unvalidated request-body routing parameters

Published
September 30, 2026
Last Modified
September 30, 2026

🔗 CVE IDs covered (1)

📋 Description

Impact

Any authenticated LiteLLM proxy user could redirect an outbound provider call to a destination they control and cause the proxy to send its own configured provider credentials to that destination. The proxy's request-body validation was a denylist that did not cover every sensitive parameter and did not inspect parameters nested inside other request fields, so a caller could supply a routing or credential value that the proxy applied without clearing the operator's stored key. Any authenticated user could therefore exfiltrate the operator's upstream provider credentials and other configured secrets, and perform Server-Side Request Forgery against internal services reachable from the proxy.

Patches

Fixed in 1.96.2, 1.95.1, 1.94.3, 1.93.2, 1.92.2, 1.91.5, 1.90.7, 1.89.7, and 1.88.6.

Workarounds

Set general_settings.allow_client_side_credentials to false so callers cannot override connection parameters, restrict proxy keys to trusted callers, and block the affected parameters (api_base, base_url, model_list, fallbacks, provider credential fields) at a reverse proxy or API gateway.

🎯 Affected products9

  • pip/litellm:< 1.88.6
  • pip/litellm:>= 1.89.0, < 1.89.7
  • pip/litellm:>= 1.90.0, < 1.90.7
  • pip/litellm:>= 1.91.0, < 1.91.5
  • pip/litellm:>= 1.92.0, < 1.92.2
  • pip/litellm:>= 1.93.0, < 1.93.2
  • pip/litellm:>= 1.94.0, < 1.94.3
  • pip/litellm:>= 1.95.0, < 1.95.1
  • pip/litellm:>= 1.96.0, < 1.96.2

🔗 References (9)