PT-2026-82662 · Pypi · Litellm

·

CVE-2026-37004

·

Published

2026-08-27

·

Updated

2026-09-10

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions litellm versions prior to 1.82.5
Description An issue exists where unauthenticated remote attackers can execute arbitrary OS commands. This occurs due to the use of an unsandboxed jinja2.Environment, which enables Server-Side Template Injection (SSTI)—a flaw where an attacker injects malicious code into a template that is then executed on the server. The flaw is triggered via the dotprompt content parameter in the '/prompts/test' endpoint.
Recommendations Update litellm to version 1.82.5 or later. As a temporary workaround, avoid using the dotprompt content parameter in the '/prompts/test' endpoint.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-37004
GHSA-6WVF-77M9-58RM
PYSEC-2026-3861

Affected Products

Litellm