SOURCE-LINKED INTELLIGENCE
GHSA-5jmr-gcrj-2c9q: LiteLLM: Arbitrary file write via path traversal in Skills archive extraction
### Impact LiteLLM Skills archive extraction did not sufficiently validate file paths from uploaded skill ZIP archives. An authenticated user with access to LiteLLM LLM API routes, or a key whose `allowed_routes` includes `/v1/skills`, `anthropic_routes`, or `llm_api_routes`, could upload a crafted skill archive containing path traversal entries. When the skill was processed for execution, those entries could be written outside the intended extraction/staging directory. This could allow arbitrary file write and may lead to code execution depending on deployment configuration and writable paths
Read original source ↗ Open in workspace
- recordType
- vulnerability
- status
- active
- evidenceStatus
- reported
- region
- Global
Evidence & attribution
- OSV AI package advisories · 2026-07-22T22:37:15.000Z
- OSV AI package advisories · 2026-07-23T11:41:48.408Z
First collected: 2026-09-20T23:41:51.992Z. This is not the publication date.