LiteLLM: Local file read via request-supplied OIDC file references
Description
Published by the National Vulnerability Database
Jul 8, 2026
Published to the GitHub Advisory Database
Jul 22, 2026
Reviewed
Jul 22, 2026
Last updated
Jul 22, 2026
Impact
LiteLLM's
/health/test_connectionendpoint resolved request-supplied environment and OIDC file references inlitellm_params. A proxy administrator, or another privileged caller with permission to test model connections, could cause LiteLLM to read files from the local filesystem via anoidc/file/reference.Because exploitation requires privileged proxy access, this is treated as a defense-in-depth issue rather than a cross-tenant privilege bypass.
Patches
The issue is fixed in
1.83.10-stable.LiteLLM recommend upgrading to
1.83.10-stableor later.Workarounds
Restrict
/health/test_connectionaccess to trusted administrators only.References