← Back to browse · API

CVE-2026-35029

Severity
HIGH
CVSS
8.7
EPSS
0.26409
Risk score
44.04
CISA KEV
No
PoC
Yes
Published
2026-04-06
Modified
2026-07-15
First seen
2026-08-07
Aliases
EUVD-2026-19370, GHSA-53MR-6C8Q-9789, PYSEC-2026-2597
Products
berriai:LiteLLM < 1.83.0, linux, redhat
Sources
euvd EUVD-2026-19370
packetstorm 893030512bdb397b1eda5375|CVE-2026-35029

Description

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.0, the /config/update endpoint does not enforce admin role authorization. A user who is already authenticated into the platform can then use this endpoint to modify proxy configuration and environment variables, register custom pass-through endpoint handlers pointing to attacker-controlled Python code, achieving remote code execution, read arbitrary server files by setting UI_LOGO_PATH and fetching via /get_image, and take over other privileged accounts by overwriting UI_USERNAME and UI_PASSWORD environment variables. Fixed in v1.83.0.

References