PT-2026-37176 · Litellm · Litellm

Jaydns

·

Published

2026-04-24

·

Updated

2026-05-22

·

CVE-2026-42203

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions LiteLLM versions 1.80.5 through 1.83.6
Description The 'POST /prompts/test' endpoint accepts user-supplied prompt templates and renders them without sandboxing. An authenticated user with a valid proxy API key can provide a crafted template to execute arbitrary code within the LiteLLM Proxy process. This may lead to the exposure of environment secrets, such as database credentials or provider API keys, and allow the execution of commands on the host system.
Recommendations Update to version 1.83.7. Block the 'POST /prompts/test' endpoint at the reverse proxy or API gateway. Review and rotate API keys that should not have access to prompt management routes.

Fix

Weakness Enumeration

Related Identifiers

CVE-2026-42203
GHSA-XQMJ-J6MV-4862

Affected Products

Litellm