Agents
LiteLLM Proxy accepts a user_config request parameter that turns it into an SSRF pivot
GHSA-hx8v-g79f-8w5f, published 2026-09-17, covers server-side request forgery in LiteLLM Proxy via the user_config request parameter, which lets a caller steer the proxy's outbound requests. LiteLLM sits in front of model traffic for a large share of self-hosted agent stacks, so the proxy usually has network reach into internal services and cloud metadata endpoints that the agent itself does not. Rated medium, but the blast radius depends entirely on where you deployed the proxy.
↳ Follow the thread