CVE-2026-37004: BerriAI litellm <=1.82.4 is vulnerable to Server-Side Template Injection (SSTI), which allows unauthenticated remote att
Summary
BerriAI litellm version 1.82.4 and earlier has a vulnerability called SSTI (server-side template injection, where attackers can inject malicious code into templates that the server processes). An attacker without authentication can send a specially crafted request to the /prompts/test endpoint that executes arbitrary OS commands (any commands on the server's operating system) because the software uses jinja2.Environment (a template processor) without proper security restrictions.
Vulnerability Details
EPSS: 0.0%
August 27, 2026
Classification
Affected Vendors
Related Issues
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-37004
First tracked: August 27, 2026 at 08:10 PM
Classified by LLM (prompt v3) · confidence: 95%