CVE-2026-59820: LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.7-stable, LiteLLM Skills archive extraction did not sufficiently validate file paths from uploade...

Added to the CISA Known Exploited Vulnerabilities catalog on 08 Jul 2026. Vendor: AI/ML. Product: LLM. CVSS score: 6.5.

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.7-stable, LiteLLM Skills archive extraction did not sufficiently validate file paths from uploaded skill ZIP archives, allowing an authenticated user with access to LiteLLM LLM API routes or a key ...

Required action: Review and patch if applicable to your AI infrastructure.