Vulnerability GHSA-hx8v-g79f-8w5f

Medium Risk
MEDIUM RISK
CVSS Score: 6.0
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
13 days ago
September 17, 2026 at 02:51 PM UTC
LiteLLM Proxy has server-side request forgery via the `user_config` request parameter
0.1.0 - 1.83.8
0.1.0 - 1.83.8

Summary

LiteLLM Proxy has server-side request forgery via the `user_config` request parameter

Details

Summary

A server-side request forgery in LiteLLM Proxy lets an authenticated caller redirect the proxy's outbound request to a host of their choosing by smuggling an api_base inside the user_config request body, bypassing the existing parameter guard.

Details

LiteLLM Proxy validates request bodies with is_request_body_safe, which blocks the api_base and base_url parameters but does not cover user_config. The user_config object is used to build the outbound router for a request, so a caller can place an api_base inside it and reach an arbitrary host. The guard only inspected the two top-level keys, so the same api_base nested inside user_config was never checked.

Exploitation requires a valid virtual key.

Impact

An authenticated caller can make the proxy issue server-side requests to internal or external hosts of their choosing, reaching endpoints the caller cannot otherwise access.

Affected / Patched

Affected: <= 1.83.8 Patched: 1.83.9

Remediation

Upgrade to 1.83.9 or later (released 2026-04-17).

Impacted packages

Timeline

Published
13 days ago
September 17, 2026 at 02:51 PM UTC
Fixed (1.83.9)
5 months ago
April 17, 2026 at 01:29 AM UTC
Last Modified
13 days ago
September 17, 2026 at 03:00 PM UTC