Skip to content
LiteLLMGHSA-6wvf-77m9-58rm

LiteLLM vulnerable to server-side template injection in the /prompts/test endpoint

Critical9.8CVE-2026-37004 · Published Aug 27, 2026 · updated Sep 10, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
litellm
PyPI
< 1.83.71.83.7
Details and references

BerriAI litellm <=1.82.4 is vulnerable to Server-Side Template Injection (SSTI), which allows unauthenticated remote attackers to execute arbitrary OS commands via a crafted dotprompt_content parameter in the /prompts/test endpoint due to use of an unsandboxed jinja2.Environment.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-1336
Also known as
CVE-2026-37004, PYSEC-2026-3861

More LiteLLM advisories

All LiteLLM
DateAdvisory
Sep 17LiteLLM Proxy has server-side request forgery via the `user_config` request parameter
CVE-2026-59823Mediumfixed in 1.83.9
Jul 22LiteLLM: Custom Code Guardrails production endpoints bypass code safety checks
CVE-2026-59821Lowfixed in 1.82.0
Jul 22LiteLLM: MCP Authentication Bypass via OAuth2 Passthrough Fallback
CVE-2026-59822Highfixed in 1.84.0
Jul 22LiteLLM: Local file read via request-supplied OIDC file references
CVE-2026-59819Lowfixed in 1.83.10
Jul 22LiteLLM: Arbitrary file write via path traversal in Skills archive extraction
CVE-2026-59820Mediumfixed in 1.83.7
Jun 21BerriAI litellm has SSRF via Unvalidated spec_path URL in MCP OpenAPI Spec Loader
CVE-2026-12798Low6.3no fix yet

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.