PT-2026-37176 · Litellm · Litellm
Jaydns
·
Published
2026-04-24
·
Updated
2026-05-22
·
CVE-2026-42203
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
LiteLLM versions 1.80.5 through 1.83.6
Description
The 'POST /prompts/test' endpoint accepts user-supplied prompt templates and renders them without sandboxing. An authenticated user with a valid proxy API key can provide a crafted template to execute arbitrary code within the LiteLLM Proxy process. This may lead to the exposure of environment secrets, such as database credentials or provider API keys, and allow the execution of commands on the host system.
Recommendations
Update to version 1.83.7.
Block the 'POST /prompts/test' endpoint at the reverse proxy or API gateway.
Review and rotate API keys that should not have access to prompt management routes.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Litellm