Server-Side Template Injection in BerriAI Litellm Software
CVE-2026-37004
9.8CRITICAL
What is CVE-2026-37004?
The BerriAI Litellm software version 1.82.4 and earlier is susceptible to Server-Side Template Injection (SSTI), which can allow unauthenticated remote attackers to execute arbitrary OS commands. This vulnerability is found in the '/prompts/test' endpoint due to the improper use of an unsandboxed jinja2.Environment. Attackers can exploit this flaw by submitting a crafted 'dotprompt_content' parameter, potentially compromising the security of the affected systems.
