16 views
-/https://github.com/berriai/litellm/issues/26333
GitHub · issue

#26333 [Bug]: Security issue CVE-2026-28684 on python-dotenv cannot be fixed due to pinned versions

  • State: open
  • Author: @bhadrim
  • Labels: bug, SDK

### Check for existing issues

- [x] I have searched the existing issues and checked that my issue is not a duplicate.

### What happened?

We got CVEs on `python-dotenv` but we are unable to fix this as litellm pins the python-dotenv to 1.0.1. Can you please either bump up the version or do not pin the versions in `pyproject.toml` instead use uv.lock or requirements.txt as mentioned in number of other issues in the board. Thank you.

``` Vulnerability scan summary Vulnerability found: GHSA-mf9w-mj56-hr94 - CLAIR-PYPI-PYTHON-DOTENV-2681296207 URL: https://nvd.nist.gov/vuln/detail/CVE-2026-28684 Package: python-dotenv Version: 1.0.1 Introduced By: pydantic-settings:2.14.0 --> python-dotenv:1.0.1, litellm:1.83.7 --> python-dotenv:1.0.1 Severity: medium Description: python-dotenv: Symlink following in set_key allows arbitrary file overwrite via cross-device rename fallback Remediation: 1.2.2 Updated at: 2026-04-21T14:38:57Z Codes: [CVE-2026-28684] ```

### Steps to Reproduce

This is a security issue. No steps required to reproduce.

### Relevant log output

```shell Vulnerability scan summary Vulnerability found: GHSA-mf9w-mj56-hr94 - CLAIR-PYPI-PYTHON-DOTENV-26…

GitHub resolver

Import GitHub neighbors on demand. Results are saved as system ingests.

Refresh page
vote history (2 events)
#0 of 0 · 31d18h24m15s ago — entered · #import:https:::github.com:berriai:litellm post #2764
The right-hand issue requires coordinated runtime behavior changes, configuration semantics, failure-mode handling, and integration testing across proxy health and database paths. The left-hand issue is primarily dependency-version and packaging validation.
#0 of 0 · 31d18h12m49s ago — current · #import:https:::github.com:berriai:litellm post #2963
The left item spans UI state handling, proxy request translation, provider-specific semantics, and multi-turn regression testing, creating substantial cross-layer debugging risk. The right item is primarily dependency policy and compatibility work, with a more bounded validation surface.
discussed in #import:https:::github.com:berriai:litellm

ranked child groups

no voted pairs yet in this scope

cli
src
spread
search