Arbitrary Code Execution in LiteLLM Proxy Server by BerriAI
CVE-2026-42203
8.6HIGH
What is CVE-2026-42203?
LiteLLM, a proxy server designed for interacting with LLM APIs, has a vulnerability that affects versions prior to 1.83.7. The /prompts/test endpoint allows authenticated users to submit user-defined prompt templates, which are processed without adequate sandboxing. This flaw enables crafted templates to execute arbitrary code within the LiteLLM Proxy process. If deployed improperly, this may expose sensitive information like provider API keys and database credentials, compromising the security of the environment. Users are encouraged to upgrade to version 1.83.7 or later, where this vulnerability has been addressed.
Affected Version(s)
litellm >= 1.80.5, < 1.83.7
