CVE 8.6 HIGH

LiteLLM: Server-Side Template Injection in /prompts/test endpoint_CVE-2026-42203

8.6 / 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N

Description

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.80.5 to before version 1.83.7, the POST /prompts/test endpoint accepted user-supplied prompt templates and rendered them without sandboxing. A crafted template could run arbitrary code inside the LiteLLM Proxy process. The endpoint only checks that the caller presents a valid proxy API key, so any authenticated user could reach it. Depending on how the proxy is deployed, this could expose secrets in the process environment (such as provider API keys or database credentials) and allow commands to be run on the host. This issue has been patched in version 1.83.7.

AI Analysis

Server-Side Template Injection vulnerability in LiteLLM's /prompts/test endpoint, allowing arbitrary code execution and potential exposure of secrets.

Basic Information

ID CVE-2026-42203
Source GitHub_M
Published May 8, 2026 at 03:36

Affected Product

Vendor BerriAI
Product litellm
Version >= 1.80.5, < 1.83.7
Affected Versions BerriAI litellm >= 1.80.5, < 1.83.7

CWE Classification

AI Assessment

AI Score 8.6 / 10
AI Severity High
Vendor BerriAI
Product LiteLLM
Version 1.80.5 to 1.83.7

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.