CRITICAL 9.8 PyPI
LiteLLM vulnerable to server-side template injection in the /prompts/test endpoint
PYSEC-2026-3861 · CVE-2026-37004 · GHSA-6wvf-77m9-58rm
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
BerriAI litellm <=1.82.4 is vulnerable to Server-Side Template Injection (SSTI), which allows unauthenticated remote attackers to execute arbitrary OS commands via a crafted dotprompt_content parameter in the /prompts/test endpoint due to use of an unsandboxed jinja2.Environment.
References
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2026-37004
- WEB https://github.com/BerriAI/litellm/commit/d910a95661fce3cdd36f3b06c03ecf9c46c6457c
- PACKAGE https://github.com/BerriAI/litellm
- WEB https://github.com/BerriAI/litellm/blob/244bdffd1bfe7bebdfdef516e1ebe426a898e2f0/litellm/proxy/prompts/prompt_endpoints.py#L1073
- WEB https://github.com/BerriAI/litellm/releases/tag/v1.83.7-stable
- WEB https://yerangamage.com/cves/detail/?slug=litellm-ssti-rce
- PACKAGE https://pypi.org/project/litellm
- ADVISORY https://github.com/advisories/GHSA-6wvf-77m9-58rm
Ready to move
Start Securing
Free, no credit card | First findings in minutes