Impact
BerriAI lesellm versions up to and including 1.82.4 are vulnerable to Server‑Side Template Injection, which allows an unauthenticated attacker to execute arbitrary operating‑system commands. The flaw stems from using an unsandboxed Jinja2 environment that evaluates attacker‑supplied template content. An attacker can trigger the vulnerability by sending a crafted dotprompt_content payload to the /prompts/test endpoint, leading to code execution under the service account.
Affected Systems
The affected product is BerriAI’s Litellm, impacting all releases up to and including version 1.82.4. Any deployment of these versions without the fix is vulnerable.
Risk and Exploitability
The CVE does not list explicit CVSS or EPSS scores, and it is not included in the CISA KEV catalog, but the nature of the flaw—unauthenticated remote code execution via a reachable HTTP endpoint—suggests a high potential impact. Once a request is made to the vulnerable endpoint, an attacker can fully control the host machine, implying critical risk until mitigated.
OpenCVE Enrichment