VDB
Sign up
—

PYSEC-2026-3476

LiteLLM: Local file read via request-supplied OIDC file references

Quick fix

PYSEC-2026-3476 — litellm: upgrade to the fixed version with the command below.

pip install --upgrade 'litellm>=1.83.10'

Details

### Impact

LiteLLM's `/health/test_connection` endpoint resolved request-supplied environment and OIDC file references in `litellm_params`. A proxy administrator, or another privileged caller with permission to test model connections, could cause LiteLLM to read files from the local filesystem via an `oidc/file/` reference.

Because exploitation requires privileged proxy access, this is treated as a defense-in-depth issue rather than a cross-tenant privilege bypass.

### Patches

The issue is fixed in `1.83.10-stable`.

LiteLLM recommend upgrading to `1.83.10-stable` or later.

### Workarounds

Restrict `/health/test_connection` access to trusted administrators only.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/litellm
Introduced in: 0Fixed in: 1.83.10
Fixpip install --upgrade 'litellm>=1.83.10'

References