CVE-2026-42203: LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.80.5 to before version 1.83.7, the POST /prompts/test endpoint accepted user-supplied prompt tem...
Added to the CISA Known Exploited Vulnerabilities catalog on 08 May 2026. Vendor: AI/ML. Product: LLM. CVSS score: 8.8.
LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.80.5 to before version 1.83.7, the POST /prompts/test endpoint accepted user-supplied prompt templates and rendered them without sandboxing. A crafted template could run arbitrary code inside the ...
Required action: Review and patch if applicable to your AI infrastructure.