VulnWatch VulnWatch
← Back to dashboard
Medium osv · PYSEC-2026-3477

LiteLLM: Arbitrary file write via path traversal in Skills archive extraction

Published Jul 23, 2026 CVSS 4.0

Impact

LiteLLM Skills archive extraction did not sufficiently validate file paths from uploaded skill ZIP archives. An authenticated user with access to LiteLLM LLM API routes, or a key whose allowed_routes includes /v1/skills, anthropic_routes, or llm_api_routes, could upload a crafted skill archive containing path traversal entries.

When the skill was processed for execution, those entries could be written outside the intended extraction/staging directory. This could allow arbitrary file write and may lead to code execution depending on deployment configuration and writable paths.

Patches

The issue is fixed in 1.83.7-stable.

LiteLLM recommens upgrading to 1.83.7-stable or later.

Workarounds

If upgrading is not immediately possible:

  1. Block POST /v1/skills at your reverse proxy or API gateway.
  2. Restrict Skills API access to trusted users only.

Affected AI Products

litellm
Get the weekly digest. Every Monday: top AI security stories of the week. Free.