CVE-2026-37004: BerriAI LiteLLM vulnerability
Published Aug 27, 2026
·Updated
BerriAI litellm <=1.82.4 is vulnerable to Server-Side Template Injection (SSTI), which allows unauthenticated remote attackers to execute arbitrary OS commands via a crafted dotpromptcontent parameter in the /prompts/test endpoint due to use of an unsandboxed jinja2.Environment.
Affected Software
1 affected component
BerriAI LiteLLM<=1.82.4
Event History
Aug 27, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·08:17 PM
Description
Frequently Asked Questions
1
Who can exploit this issue?
An unauthenticated remote attacker can exploit it if they can reach the /prompts/test endpoint and submit a crafted dotprompt_content parameter.
2
What is the potential impact of successful exploitation?
Successful exploitation can result in arbitrary operating-system command execution on the affected LiteLLM host.
3
Which LiteLLM versions are affected?
BerriAI LiteLLM versions 1.82.4 and earlier are identified as vulnerable.