Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-37004: LiteLLM can run remote commands via prompts test
CVE-2026-37004 · published 1 month ago
Summary
The LiteLLM software (versions up to 1.82.4) lets anyone on the internet send specially crafted data to the /prompts/test page and cause the server to run any command it wants. This could let attackers take control of the server or steal data. Upgrade to a newer version of LiteLLM or apply the vendor's patch, and limit access to the endpoint to trusted users only.
What to do
- Update litellm to version 1.83.7.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| pip | – | litellm |
< 1.83.7 Fix: upgrade to 1.83.7
|
Original advisory text
LiteLLM vulnerable to server-side template injection in the /prompts/test endpoint
BerriAI litellm <=1.82.4 is vulnerable to Server-Side Template Injection (SSTI), which allows unauthenticated remote attackers to execute arbitrary OS commands via a crafted dotprompt_content parameter in the /prompts/test endpoint due to use of an unsandboxed jinja2.Environment.
References
- https://nvd.nist.gov/vuln/detail/CVE-2026-37004
- https://github.com/advisories/GHSA-6wvf-77m9-58rm
- https://github.com/BerriAI/litellm/commit/d910a95661fce3cdd36f3b06c03ecf9c46c645...
- https://github.com/BerriAI/litellm Product
- https://github.com/BerriAI/litellm/blob/244bdffd1bfe7bebdfdef516e1ebe426a898e2f0...
- https://pypi.org/project/litellm Product
- https://yerangamage.com/cves/detail/?slug=litellm-ssti-rce
- https://github.com/BerriAI/litellm/releases/tag/v1.83.7-stable
Internet-facing
3 days
Internal
60 days
- Not known to be exploited
- Can be exploited automatically
- Gives an attacker full control
Severity
9.8
Critical
Type
CWE-1336Improper Neutralization of Special Elements Used in a Template Engine
Timeline
Published27 Aug 2026
Updated7 Oct 2026
First seen27 Aug 2026
Sources
CVE-2026-37004 · NVD
CVE-2026-37004 · MITRE
GHSA-6wvf-77m9-58rm · GHSA
PYSEC-2026-3861 · OSV
Track software like this
Free during beta