Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-37004: BerriAI litellm up to 1.82.4 lets attackers run commands

CVE-2026-37004 · published 7 days ago
Summary

The litellm library used by BerriAI, in versions up to 1.82.4, can be tricked into running any operating‑system command if someone sends a specially crafted request to its /prompts/test page. This can happen without any login, giving a remote attacker full control over the server that runs the software. Update litellm to a newer version or apply the vendor’s patch and limit public access to the affected endpoint.

Original advisory text
BerriAI litellm <=1.82.4 is vulnerable to Server-Side Template Injection (SSTI), which allows unauthenticated remote attackers to execute arbitrary OS commands via a crafted dotprompt_content param...
BerriAI litellm <=1.82.4 is vulnerable to Server-Side Template Injection (SSTI), which allows unauthenticated remote attackers to execute arbitrary OS commands via a crafted dotprompt_content parameter in the /prompts/test endpoint due to use of an unsandboxed jinja2.Environment.
Severity
9.8 Critical
Exploitation
EPSS <1%
Type
CWE-1336Improper Neutralization of Special Elements Used in a Template Engine
Timeline
Published27 Aug 2026
Updated2 Sep 2026
First seen27 Aug 2026
Sources
CVE-2026-37004 · MITRE
Monitor software like this
Free during beta