CVE-2026-37004Critical· 9.8▾ MidnightLiteLLM vulnerable to server-side template injection in the /prompts/test endpoint
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 53.9 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
0.5%
Last analysed / modified upstream
BerriAI litellm <=1.82.4 is vulnerable to Server-Side Template Injection (SSTI), which allows unauthenticated remote attackers to execute arbitrary OS commands via a crafted dotprompt_content parameter in the /prompts/test endpoint due to use of an unsandboxed jinja2.Environment.
litellm < 1.83.7Upgrade to a patched release:
litellm 1.83.7Connected by shared product, vendor, weakness, or advisory.
CVE-2026-42203HighLiteLLM: Server-Side Template Injection in /prompts/test endpoint
CVE-2026-59820Medium· 6.5LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format
CVE-2024-2952Critical· 9.8LiteLLM has Server-Side Template Injection vulnerability in /completions endpoint
CVE-2026-47101High· 8.8LiteLLM prior to 1.83.14 allows an authenticated internal_user to create API keys with access to routes that their role does not permit
CVE-2026-42271High· 8.8LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format
CVE-2026-49468Critical· 9.8LiteLLM: Authentication Bypass via Host Header Injection