External risk intelligence

BerriAI LiteLLM SSTI Vulnerability Allows Remote Command Execution.

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-37004

The vulnerability exists in an API endpoint (/prompts/test) within a proxy service (LiteLLM). Proxy services and API gateways are commonly deployed as internet-facing or edge services to facilitate LLM request routing, making this endpoint potentially reachable from the public internet in standard deployment patterns.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical security vulnerability has been identified in the litellm software, specifically affecting its handling of server-side template injection. This flaw could allow remote attackers to execute unauthorized commands on the underlying operating system without needing any credentials, posing a significant risk to systems utilizing this technology.

  • Unauthenticated remote attackers can run commands.
  • Critical issue in templating, impacting command execution.
  • Confirm relevance and assess exposure to this risk.

Attack Path

How an attacker could exploit the issue

An attacker can exploit this vulnerability by sending a specially crafted request to the `/prompts/test` endpoint without needing to authenticate. This request would target the `dotprompt_content` parameter, which is processed using an unsandboxed templating engine. Successful exploitation could allow the attacker to execute arbitrary operating system commands on the server.

  • Unauthenticated access to the `/prompts/test` endpoint.
  • Crafted `dotprompt_content` parameter in a request.
  • Remote command execution on the server.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow unauthenticated attackers to execute arbitrary operating system commands. This may occur when the `/prompts/test` endpoint is accessed with a specially crafted `dotprompt_content` parameter, bypassing intended security measures due to the use of an unsandboxed Jinja2 environment.

  • OS command execution.
  • Via crafted `dotprompt_content` parameter.
  • Compromise of the server.

Operational Fix

Recommended remediation, mitigation, and detection steps

The litellm proxy, particularly the `/prompts/test` endpoint, is likely managed by platform or application teams responsible for LLM services. The first step is to identify all instances of litellm, determine their network exposure and business criticality, and then locate the accountable owner for remediation planning.

  • Platform or application teams own this.
  • Verify litellm instances and exposure.
  • Plan remediation based on identified risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is BerriAI LiteLLM?

LiteLLM is a proxy server designed to standardize interactions with various Large Language Models. It acts as an interface that translates API calls, allowing developers to switch between different LLM providers easily. Organizations use it to manage and route LLM requests efficiently within their infrastructure.

What is the vulnerability in CVE-2026-37004?

This vulnerability is a Server-Side Template Injection, or CWE-1336. It occurs because the software processes user-provided input using an unsandboxed template engine. Instead of just treating the input as data, the system incorrectly interprets and executes the input as code on the server, leading to potential command execution.

How can an attacker trigger this vulnerability?

An attacker triggers this by sending a specially crafted request to the /prompts/test endpoint. Specifically, they must inject malicious content into the dotprompt_content parameter. Requests that do not target this specific parameter or the /prompts/test endpoint do not trigger this flaw.

Is my LiteLLM instance at risk?

According to Halo Surface Signal, this vulnerability is significant if your LiteLLM instance is internet-facing. Because the /prompts/test endpoint is part of a proxy service, it is often exposed to the public internet to facilitate request routing, which makes it reachable by remote attackers.

What should I do if I run LiteLLM?

First, locate all running instances of LiteLLM within your environment to understand your footprint. Confirm whether your specific deployment exposes the /prompts/test endpoint to the network. Once identified, coordinate with your technical team to prioritize these systems for risk assessment and pending remediation.

References