VYPR
Unrated severityNVD Advisory· Published Aug 27, 2026

CVE-2026-37004

CVE-2026-37004

Description

BerriAI litellm <=1.82.4 is vulnerable to Server-Side Template Injection (SSTI), which allows unauthenticated remote attackers to execute arbitrary OS commands via a crafted dotprompt_content parameter in the /prompts/test endpoint due to use of an unsandboxed jinja2.Environment.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • Berriai/Litellmreferences2 versions
    (expand)+ 1 more
    • (no CPE)
    • (no CPE)range: <=1.82.4

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.

CVE-2026-37004 · VYPR