PT-2026-82662 · Pypi · Litellm
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
litellm versions prior to 1.82.5
Description
An issue exists where unauthenticated remote attackers can execute arbitrary OS commands. This occurs due to the use of an unsandboxed jinja2.Environment, which enables Server-Side Template Injection (SSTI)—a flaw where an attacker injects malicious code into a template that is then executed on the server. The flaw is triggered via the
dotprompt content parameter in the '/prompts/test' endpoint.Recommendations
Update litellm to version 1.82.5 or later.
As a temporary workaround, avoid using the
dotprompt content parameter in the '/prompts/test' endpoint.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Litellm