Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
3529 articles · 209755 vulns · 37/41 feeds (7d)
← Back to list
—
CVE-2026-59821KEVEXPLOITEDPATCHED
BerriAI · litellm

LiteLLM: Custom Code Guardrails production endpoints bypass code safety checks

Description

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.82.0-stable, LiteLLM's Custom Code Guardrails production create and update paths did not apply the same sandboxing and validation used by the test endpoint, allowing a privileged user with access to create or update guardrails to submit custom Python code that executed in the LiteLLM proxy environment and could expose secrets available to the process. This issue is fixed in version 1.82.0-stable.

Affected Products

VendorProductVersions
BerriAIlitellmpip/litellm: < 1.82.0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
open sourcelitellmcert_advisory90%

References

  • https://github.com/BerriAI/litellm/security/advisories/GHSA-72m8-9m7m-h278(x_refsource_CONFIRM)
  • https://github.com/BerriAI/litellm/commit/e50b4486d0f7aa0497185a1ebcdd2c91f1769eba(x_refsource_MISC)
  • https://github.com/BerriAI/litellm/releases/tag/v1.82.0-stable(x_refsource_MISC)

Related News (2 articles)

Tier B
BSI Advisories57d ago
[NEU] [hoch] LiteLLM: Mehrere Schwachstellen
→ No new info (linked only)
Tier C
VulDB57d ago
CVE-2026-59821 | BerriAI litellm up to 1.65.4 Custom Code Guardrails sandbox
→ No new info (linked only)

Discussion (0)

Loading…

CISA KEV✅ Yes
Actively exploited✅ Yes
Patch available
litellm@1.82.0
CWECWE-94
PublishedJul 8, 2026
Last enriched57d agov2
Trending Score0
Source articles2
Independent2
Info Completeness7/14
Missing: cvss, epss, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

NONECVE-2026-59822EXPKEV
LiteLLM: MCP Authentication Bypass via OAuth2 Passthrough Fallback
Trending: 127
MEDIUMCVE-2026-84377EXP
LiteLLM: Authenticated SSRF and provider-credential exfiltration via unvalidated request-body routing parameters
Trending: 46
LOWCVE-2026-59819
LiteLLM: Local file read via request-supplied OIDC file references
NONECVE-2026-12799EXP
BerriAI litellm Incomplete Fix CVE-2025-0628 internal_user_endpoints.py ui_view_users improper authorization
NONECVE-2026-12796
BerriAI litellm SSO Authentication Flow ui_sso.py get_redirect_response_from_openid session expiration

Pin to Dashboard

Verification

State: verified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 8, 2026
Added to CISA KEV
Jul 8, 2026
Discovered by ZDM
Jul 8, 2026
Updated: affectedVersions
Jul 8, 2026
Actively Exploited
Jul 9, 2026
Patch Available
Jul 9, 2026

Version History

v2
Last enriched 57d ago
v2Tier C57d ago

Updated affected versions to include 1.65.4 and changed severity to HIGH.

affectedVersions
via VulDB
v157d ago

Initial creation