CVE-2026-42203 is a server-side template injection vulnerability in LiteLLM Proxy versions 1.80.5 through 1.83.6. The prompt-testing endpoint renders user-supplied prompt templates without sandboxing, allowing a crafted template to execute arbitrary code within the proxy process. Access requires only a valid proxy API key, making the vulnerability accessible to any authenticated proxy user. Exploitation can expose process-environment secrets and, depending on deployment, permit command execution on the host. The vulnerability was fixed in version 1.83.7.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small, self-contained proof-of-concept exploit for CVE-2026-42203 affecting LiteLLM's /prompts/test functionality. The main exploit logic is in CVE_2026_42203.py, a Python script that builds a malicious dotprompt payload containing a Jinja SSTI expression: it reaches into cycler.__init__.__globals__.os and invokes os.popen() to execute a command on the target. The executed command is a Python one-liner that performs an HTTP request to a randomized CEYE subdomain, allowing blind confirmation of remote code execution through an out-of-band callback. Operational flow: the script accepts a target URL, LiteLLM API key, CEYE token, and CEYE domain; generates a random filter string; constructs callback URL http://<random>.<ceye-domain>/; embeds that into the SSTI payload; sends the payload to POST /prompts/test with Bearer authentication; then polls http://api.ceye.io/v1/records until the callback appears or a timeout expires. Exit codes distinguish vulnerable, not vulnerable, configuration error, and inconclusive states. Repository structure is minimal: one Python exploit, one README with usage instructions, and a Lab directory containing docker-compose.yaml plus litellm_config.yaml to reproduce a local vulnerable environment. The lab deploys PostgreSQL and LiteLLM on port 4000, with a sample master key and config mount. This is not merely a detector: it attempts actual code execution on the target, but the payload is fixed to an outbound HTTP callback rather than an interactive shell, so OPERATIONAL is the best maturity fit rather than WEAPONIZED.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A network-accessible vulnerability requiring low privileges and no user interaction, with high confidentiality and integrity impacts according to the supplied CVSS vectors. The affected product and underlying flaw are not identified. Exploits and a patch are reported as available.
A server-side template injection vulnerability in LiteLLM's POST /prompts/test endpoint that can lead to code execution in the LiteLLM Proxy process, but requires authentication with a valid proxy API key.
An authenticated remote code execution vulnerability in LiteLLM Proxy caused by unsandboxed rendering of user-supplied prompt templates in the POST /prompts/test endpoint.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.