Vulnerability PYSEC-2026-3861

Critical
CRITICAL RISK
CVSS Score: 9.8
Score Range: 9.0–10.0
Critical severity vulnerabilities (CVSS 9.0–10.0). These represent the highest impact issues.
20 days ago
September 10, 2026 at 09:44 AM UTC
LiteLLM vulnerable to server-side template injection in the /prompts/test endpoint
0.1.0 - 1.83.6
0.1.0 - 1.83.6

Summary

LiteLLM vulnerable to server-side template injection in the /prompts/test endpoint

Details

BerriAI litellm <=1.82.4 is vulnerable to Server-Side Template Injection (SSTI), which allows unauthenticated remote attackers to execute arbitrary OS commands via a crafted dotprompt_content parameter in the /prompts/test endpoint due to use of an unsandboxed jinja2.Environment.

Impacted packages

Timeline

Published
20 days ago
September 10, 2026 at 09:44 AM UTC
Fixed (1.83.7)
5 months ago
April 13, 2026 at 05:34 PM UTC
Last Modified
20 days ago
September 10, 2026 at 12:15 PM UTC