PT-2026-53472 · Pypi · Litellm
Published
2026-06-29
·
Updated
2026-06-29
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
BerriAI/litellm is vulnerable to Server-Side Template Injection (SSTI) via the
/completions endpoint. The vulnerability arises from the hf chat template method processing the chat template parameter from the tokenizer config.json file through the Jinja template engine without proper sanitization. Attackers can exploit this by crafting malicious tokenizer config.json files that execute arbitrary code on the server.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Litellm