CRITICAL
9.8 CVE-2026-37004 Published 27 Aug 2026
BerriAI litellm SSTI Vulnerability
Worried this affects one of your servers?
BerriAI litellm versions <=1.82.4 are affected by a Server-Side Template Injection (SSTI) vulnerability.
Unauthenticated attackers can exploit this by sending a crafted dotprompt_content parameter to the /prompts/test endpoint, allowing them to execute arbitrary OS commands.
This is due to the use of an unsandboxed jinja2.Environment.
Reference: CVE-2026-37004 on NVD
← Back to Security News