Skip to content
LiteLLMGHSA-qrc4-49gv-mv9m

LiteLLM allows an authenticated internal_user to create API keys with access to routes that their role does not permit

High8.8CVE-2026-47101 · Published May 21, 2026 · updated Sep 10, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
litellm
PyPI
< 1.83.141.83.14
Details and references

LiteLLM prior to 1.83.14 allows an authenticated internal_user to create API keys with access to routes that their role does not permit. When generating a key, the allowed_routes field is stored without verifying that the specified routes fall within the user's own permissions. A key created with access to admin-only routes can then be used to reach those routes successfully, bypassing the role-based access controls that would otherwise block the request, enabling full privilege escalation from internal_user to proxy_admin.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-863
Also known as
CVE-2026-47101, PYSEC-2026-2598

More LiteLLM advisories

All LiteLLM
DateAdvisory
May 21LiteLLM allows a user to modify their own user_role via the /user/update endpoint
CVE-2026-47102High8.8fixed in 1.83.10
May 11LiteLLM has a sandbox escape in custom-code guardrail
CVE-2026-40217High8.8fixed in 1.83.10
Apr 25LiteLLM: Authenticated command execution via MCP stdio test endpoints
CVE-2026-42271High8.8fixed in 1.83.7
Apr 24LiteLLM has SQL Injection in Proxy API key verification
CVE-2026-42208Critical9.8fixed in 1.83.7
Apr 24LiteLLM: Server-Side Template Injection in /prompts/test endpoint
CVE-2026-42203Highfixed in 1.83.7
Jun 16LiteLLM: Authentication Bypass via Host Header Injection
CVE-2026-49468Critical9.8fixed in 1.84.0

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.