A server-side request forgery in LiteLLM Proxy lets an authenticated caller redirect the
proxy's outbound request to a host of their choosing by smuggling an api_base inside the
user_config request body, bypassing the existing parameter guard.
LiteLLM Proxy validates request bodies with is_request_body_safe, which blocks the
api_base and base_url parameters but does not cover user_config. The user_config
object is used to build the outbound router for a request, so a caller can place an
api_base inside it and reach an arbitrary host. The guard only inspected the two
top-level keys, so the same api_base nested inside user_config was never checked.
Exploitation requires a valid virtual key.
An authenticated caller can make the proxy issue server-side requests to internal or external hosts of their choosing, reaching endpoints the caller cannot otherwise access.
Affected: <= 1.83.8
Patched: 1.83.9
Upgrade to 1.83.9 or later (released 2026-04-17).
{
"cwe_ids": [
"CWE-918"
],
"github_reviewed": true,
"github_reviewed_at": "2026-09-17T14:51:21Z",
"nvd_published_at": "2026-09-16T19:17:21Z",
"severity": "MODERATE"
}