CVE-2026-42203General(litellm / litellm)

LOWCVSS 8.8 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch litellm litellm systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.80.5 to before version 1.83.7, the POST /prompts/test endpoint accepted user-supplied prompt templates and rendered them without sandboxing. A crafted template could run arbitrary code inside the LiteLLM Proxy process. The endpoint only checks that the caller presents a valid proxy API key, so any authenticated user could reach it. Depending on how the proxy is deployed, this could expose secrets in the process environment (such as provider API keys or database credentials) and allow commands to be run on the host. This issue has been patched in version 1.83.7.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-1336CWE-94

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • litellm

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-05-09); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
litellm

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-05-08: 1Mentions · 2026-05-09: 2Mentions · 2026-05-22: 1PoC Mentioned / Linked · 2026-05-22: 1Patch / Workaround · 2026-05-22: 1Technical Details · 2026-05-09: 1Technical Details · 2026-05-22: 105-0805-0905-22
Signal classification3 categories
General
250.0%
Disclosure
125.0%
PoC
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-05-081
General1
2026-05-092
Disclosure1General1
2026-05-221
PoC1
Full discourse4 posts
  • CCB Alert@CCBalert
    PoC

    Warning: #Vulnerability in #LightLLM #CVE-2026-42203 CVSS: 8.8. An improper neutralisation in the template engine allows attackers to escape the sandbox and run arbitrary code. #PoC available. Read https://github.com/BerriAI/litellm/security/advisories/GHSA-xqmj-j6mv-4862 and #Patch #Patch #Patch

    Post summary

    The post announces a high‑severity CVE in LightLLM, confirms a PoC is available, and references a patch advisory, indicating the vulnerability is publicly disclosed and mitigated.

    00010253
    7.2K followersView on X
  • CVE@CVEnew
    General

    CVE-2026-42203 LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.80.5 to before version 1.83.7, the POST /prompts/test endpoint ac… https://www.cve.org/CVERecord?id=CVE-2026-42203

    Post summary

    The text offers a brief technical description of CVE‑2026‑42203 concerning LiteLLM’s prompt endpoint, but it contains no proof‑of‑concept, exploit code, active exploitation report, patch information, or debunking claim.

    00010229
    57.5K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-42203 LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.80.5 to before version 1.83.7, the POST /prompts/test endpoint ac… https://www.cve.org/CVERecord?id=CVE-2026-42203 ----- Traducción: CVE-2026-42203 Lit… http://infoflow.cloud`

    Post summary

    The tweet announces CVE-2026-42203 for LiteLLM, noting affected versions and a specific endpoint, but it does not disclose a PoC, exploit, active attacks, patch, or detailed technical vulnerability information.

    0000032
    76 followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-42203 📊 Severity: 8.6 🚨 Risk Level: High 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-42203 #CVE-2026-42203 #CVE #High #CyberSecurity #InfoSec https://t.co/bd4qfNZZYh

    Post summary

    A newly announced high‑severity CVE (CVE‑2026‑42203) is reported with minimal details; no PoC, exploit, active use, or patches are discussed.

    0000053
    157 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applitellmlitellm---

Explore more