VDB
Sign up
MEDIUM

GHSA-hx8v-g79f-8w5f

LiteLLM Proxy has server-side request forgery via the `user_config` request parameter

Quick fix

GHSA-hx8v-g79f-8w5f — litellm: upgrade to the fixed version with the command below.

pip install --upgrade 'litellm>=1.83.9'

Details

### Summary A server-side request forgery in LiteLLM Proxy lets an authenticated caller redirect the proxy's outbound request to a host of their choosing by smuggling an `api_base` inside the `user_config` request body, bypassing the existing parameter guard.

### Details LiteLLM Proxy validates request bodies with `is_request_body_safe`, which blocks the `api_base` and `base_url` parameters but does not cover `user_config`. The `user_config` object is used to build the outbound router for a request, so a caller can place an `api_base` inside it and reach an arbitrary host. The guard only inspected the two top-level keys, so the same `api_base` nested inside `user_config` was never checked.

Exploitation requires a valid virtual key.

### Impact An authenticated caller can make the proxy issue server-side requests to internal or external hosts of their choosing, reaching endpoints the caller cannot otherwise access.

### Affected / Patched Affected: `<= 1.83.8` Patched: `1.83.9`

### Remediation Upgrade to 1.83.9 or later (released 2026-04-17).

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/litellm
Introduced in: 0Fixed in: 1.83.9
Fixpip install --upgrade 'litellm>=1.83.9'

References