Executive brief
LiteLLM is an AI gateway used to manage and proxy requests to various Large Language Model (LLM) providers. A security flaw in the software allows authenticated users to execute malicious code on the server by submitting specially crafted prompt templates. This could lead to the theft of sensitive API keys, access to internal databases, or full control over the host system.
Technical details
A Server-Side Template Injection (SSTI) vulnerability exists in LiteLLM's '/prompts/test' endpoint due to improper neutralization of special elements in template engines (CWE-1336). The endpoint accepts user-supplied prompt templates and renders them without a sandbox environment. An attacker with a valid proxy API key can submit a crafted template to execute arbitrary Python code within the context of the LiteLLM Proxy process. This can result in the exposure of environment variables (including provider API keys and database credentials) and remote command execution on the underlying host. The issue is resolved in version 1.83.7 by implementing a sandboxed rendering environment.
Affected products
- BerriAI litellm >= 1.80.5, < 1.83.7
Timeline
- 2026-04-19: patched: Version 1.83.7-stable released
- 2026-04-20: advisory: GitHub Security Advisory published
- 2026-05-08: disclosed: NVD publication date
References
- https://github.com/BerriAI/litellm/releases/tag/v1.83.7-stable
- https://github.com/BerriAI/litellm/security/advisories/GHSA-xqmj-j6mv-4862
- https://access.redhat.com/security/cve/CVE-2026-42203
- https://bugzilla.redhat.com/show_bug.cgi?id=2467917
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42203.json