GHSA-6wvf-77m9-58rmCriticalCVSS 9.8

LiteLLM vulnerable to server-side template injection in the /prompts/test endpoint

Published
August 27, 2026
Last Modified
September 8, 2026

🔗 CVE IDs covered (1)

📋 Description

BerriAI litellm <=1.82.4 is vulnerable to Server-Side Template Injection (SSTI), which allows unauthenticated remote attackers to execute arbitrary OS commands via a crafted dotprompt_content parameter in the /prompts/test endpoint due to use of an unsandboxed jinja2.Environment.

🎯 Affected products1

  • pip/litellm:< 1.83.7

🔗 References (6)