Impact
BerriAI litellm versions up to 1.82.4 are vulnerable to Server‑Side Template Injection caused by an unsandboxed Jinja2 environment. An attacker can supply a crafted dotprompt_content parameter to the /prompts/test endpoint, which is evaluated as a Jinja2 template. This evaluation leads to the execution of arbitrary operating‑system commands, giving the attacker full control over the service host.
Affected Systems
The affected product is BerriAI litellm, with all releases up to and including version 1.82.4 impacted. Any deployment of these versions that has not applied a fix remains vulnerable.
Risk and Exploitability
The CVSS score is 9.8 and the EPSS score is less than 1 %. While the exploitation probability is low, the impact of successful exploitation is catastrophic: remote code execution without authentication. The vulnerability is accessed via a reachable HTTP endpoint, and no KEV listing indicates it has not yet been widely exploited in the wild, but the flaw’s severity warrants urgent remediation.
OpenCVE Enrichment
Github GHSA