From b391f772ade4fb7f930e6ed2cfd7425c579fd016 Mon Sep 17 00:00:00 2001 From: Cursor Agent Date: Thu, 28 May 2026 06:23:21 +0000 Subject: [PATCH] fix(batch-rate-limiter): prevent user metadata flag from bypassing model allowlist The skip_batch_input_file_rate_limiting flag in litellm_metadata is user-controllable for batch requests (request-body metadata lands in litellm_metadata via LITELLM_METADATA_ROUTES). Honoring it unconditionally also skipped _enforce_batch_file_model_access, letting a restricted key submit a JSONL referencing models outside its allowlist. Only honor the metadata-based skip when the key has no model allowlist to enforce. Co-authored-by: Yassin Kortam --- litellm/proxy/hooks/batch_rate_limiter.py | 11 ++++++++++- 1 file changed, 10 insertions(+), 1 deletion(-) diff --git a/litellm/proxy/hooks/batch_rate_limiter.py b/litellm/proxy/hooks/batch_rate_limiter.py index cc5a1400a9d..6b8dca3e8c4 100644 --- a/litellm/proxy/hooks/batch_rate_limiter.py +++ b/litellm/proxy/hooks/batch_rate_limiter.py @@ -151,8 +151,17 @@ class _PROXY_BatchRateLimiter(CustomLogger): if general_settings.get("disable_batch_input_file_rate_limiting") is True: return True + # Only honor the metadata-based skip when the key has no model + # allowlist to enforce. Otherwise a caller could set this flag in + # the request body (it lands in ``litellm_metadata`` for batch + # routes) and skip ``_enforce_batch_file_model_access``, smuggling + # restricted models into the JSONL. litellm_metadata = data.get("litellm_metadata") or {} - if litellm_metadata.get("skip_batch_input_file_rate_limiting") is True: + if litellm_metadata.get( + "skip_batch_input_file_rate_limiting" + ) is True and not self._key_requires_batch_model_access_check( + user_api_key_dict + ): return True batch_model = self._get_batch_routing_model(data)