CRITICAL 9.8 CVE-2026-37004 Published 27 Aug 2026

BerriAI litellm SSTI Vulnerability

Worried this affects one of your servers?

BerriAI litellm versions <=1.82.4 are affected by a Server-Side Template Injection (SSTI) vulnerability.

Unauthenticated attackers can exploit this by sending a crafted dotprompt_content parameter to the /prompts/test endpoint, allowing them to execute arbitrary OS commands.

This is due to the use of an unsandboxed jinja2.Environment.

Reference: CVE-2026-37004 on NVD

← Back to Security News