AIIC AI Intelligence Centre

SOURCE-LINKED INTELLIGENCE

GHSA-6wvf-77m9-58rm: LiteLLM vulnerable to server-side template injection in the /prompts/test endpoint

OSV AI package advisories · observation · Aug 27, 2026 · UTC

BerriAI litellm <=1.82.4 is vulnerable to Server-Side Template Injection (SSTI), which allows unauthenticated remote attackers to execute arbitrary OS commands via a crafted dotprompt_content parameter in the /prompts/test endpoint due to use of an unsandboxed jinja2.Environment.

Read original source ↗ Open in workspace

recordType
vulnerability
status
active
evidenceStatus
reported
region
Global

Evidence & attribution

First collected: 2026-09-20T23:41:51.992Z. This is not the publication date.