CRITICAL 9.8 PyPI

LiteLLM vulnerable to server-side template injection in the /prompts/test endpoint

PYSEC-2026-3861 · CVE-2026-37004 · GHSA-6wvf-77m9-58rm

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

BerriAI litellm <=1.82.4 is vulnerable to Server-Side Template Injection (SSTI), which allows unauthenticated remote attackers to execute arbitrary OS commands via a crafted dotprompt_content parameter in the /prompts/test endpoint due to use of an unsandboxed jinja2.Environment.

Ready to move

Start Securing

Free, no credit card | First findings in minutes