AIIC AI Intelligence Centre

SOURCE-LINKED INTELLIGENCE

GHSA-hx8v-g79f-8w5f: LiteLLM Proxy has server-side request forgery via the `user_config` request parameter

OSV AI package advisories · observation · Sep 17, 2026 · UTC

### Summary A server-side request forgery in LiteLLM Proxy lets an authenticated caller redirect the proxy's outbound request to a host of their choosing by smuggling an `api_base` inside the `user_config` request body, bypassing the existing parameter guard. ### Details LiteLLM Proxy validates request bodies with `is_request_body_safe`, which blocks the `api_base` and `base_url` parameters but does not cover `user_config`. The `user_config` object is used to build the outbound router for a request, so a caller can place an `api_base` inside it and reach an arbitrary host. The guard only inspe

Read original source ↗ Open in workspace

recordType
vulnerability
status
active
evidenceStatus
reported
region
Global

Evidence & attribution

First collected: 2026-09-20T23:41:51.992Z. This is not the publication date.