LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.80.5 to before version 1.83.7, the POST /prompts/test endpoint accepted user-supplied prompt templates and rendered them without sandboxing. A crafted template could run arbitrary code inside the LiteLLM Proxy process. The endpoint only checks that the caller presents a valid proxy API key, so any authenticated user could reach it. Depending on how the proxy is deployed, this could expose secrets in the process environment (such as provider API keys or database credentials) and allow commands to be run on the host. This issue has been patched in version 1.83.7.
References
| Link | Resource |
|---|---|
| https://github.com/BerriAI/litellm/releases/tag/v1.83.7-stable | Product Release Notes |
| https://github.com/BerriAI/litellm/security/advisories/GHSA-xqmj-j6mv-4862 | Mitigation Patch Vendor Advisory |
Configurations
History
13 May 2026, 17:14
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/BerriAI/litellm/releases/tag/v1.83.7-stable - Product, Release Notes | |
| References | () https://github.com/BerriAI/litellm/security/advisories/GHSA-xqmj-j6mv-4862 - Mitigation, Patch, Vendor Advisory | |
| First Time |
Litellm litellm
Litellm |
|
| CPE | cpe:2.3:a:litellm:litellm:*:*:*:*:*:*:*:* | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.8 |
08 May 2026, 04:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-08 04:16
Updated : 2026-05-13 17:14
NVD link : CVE-2026-42203
Mitre link : CVE-2026-42203
CVE.ORG link : CVE-2026-42203
JSON object : View
Products Affected
litellm
- litellm
CWE
CWE-1336
Improper Neutralization of Special Elements Used in a Template Engine
