{
  "document": {
    "aggregate_severity": {
      "namespace": "https://access.redhat.com/security/updates/classification/",
      "text": "Important"
    },
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "distribution": {
      "text": "Copyright © Red Hat, Inc. All rights reserved.",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original.",
        "title": "Terms of Use"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://access.redhat.com/security/team/contact/",
      "issuing_authority": "Red Hat Product Security is responsible for vulnerability handling across all Red Hat products and services.",
      "name": "Red Hat Product Security",
      "namespace": "https://www.redhat.com"
    },
    "references": [
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42203.json"
      }
    ],
    "title": "litellm: LiteLLM: Arbitrary code execution via unsandboxed prompt templates",
    "tracking": {
      "current_release_date": "2026-06-30T03:57:10+00:00",
      "generator": {
        "date": "2026-06-30T03:57:10+00:00",
        "engine": {
          "name": "Red Hat SDEngine",
          "version": "5.3.0"
        }
      },
      "id": "CVE-2026-42203",
      "initial_release_date": "2026-05-08T03:36:58.648000+00:00",
      "revision_history": [
        {
          "date": "2026-05-08T03:36:58.648000+00:00",
          "number": "1",
          "summary": "Initial version"
        },
        {
          "date": "2026-05-18T12:38:23+00:00",
          "number": "2",
          "summary": "Current version"
        },
        {
          "date": "2026-06-30T03:57:10+00:00",
          "number": "3",
          "summary": "Last generated version"
        }
      ],
      "status": "final",
      "version": "3"
    }
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Exploit Intelligence",
                "product": {
                  "name": "Exploit Intelligence",
                  "product_id": "exploit_intelligence",
                  "product_identification_helper": {
                    "cpe": "cpe:/a:redhat:exploit_intelligence:0"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Exploit Intelligence"
          },
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Red Hat Ansible Automation Platform 2",
                "product": {
                  "name": "Red Hat Ansible Automation Platform 2",
                  "product_id": "red_hat_ansible_automation_platform_2",
                  "product_identification_helper": {
                    "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Red Hat Ansible Automation Platform 2"
          },
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Red Hat OpenShift AI (RHOAI)",
                "product": {
                  "name": "Red Hat OpenShift AI (RHOAI)",
                  "product_id": "red_hat_openshift_ai_(rhoai)",
                  "product_identification_helper": {
                    "cpe": "cpe:/a:redhat:openshift_ai"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Red Hat OpenShift AI (RHOAI)"
          },
          {
            "category": "product_version",
            "name": "exploit-intelligence-tech-preview/vulnerability-analysis-rhel9",
            "product": {
              "name": "exploit-intelligence-tech-preview/vulnerability-analysis-rhel9",
              "product_id": "exploit-intelligence-tech-preview/vulnerability-analysis-rhel9",
              "product_identification_helper": {
                "purl": "pkg:oci/vulnerability-analysis-rhel9?repository_url=registry.redhat.io/exploit-intelligence-tech-preview/vulnerability-analysis-rhel9"
              }
            }
          },
          {
            "category": "product_version",
            "name": "ansible-automation-platform-26/lightspeed-chatbot-rhel9",
            "product": {
              "name": "ansible-automation-platform-26/lightspeed-chatbot-rhel9",
              "product_id": "ansible-automation-platform-26/lightspeed-chatbot-rhel9",
              "product_identification_helper": {
                "purl": "pkg:oci/lightspeed-chatbot-rhel9?repository_url=registry.redhat.io/ansible-automation-platform-26/lightspeed-chatbot-rhel9"
              }
            }
          },
          {
            "category": "product_version",
            "name": "rhoai/odh-llama-stack-core-rhel9",
            "product": {
              "name": "rhoai/odh-llama-stack-core-rhel9",
              "product_id": "rhoai/odh-llama-stack-core-rhel9",
              "product_identification_helper": {
                "purl": "pkg:oci/odh-llama-stack-core-rhel9?repository_url=registry.redhat.io/rhoai/odh-llama-stack-core-rhel9"
              }
            }
          }
        ],
        "category": "vendor",
        "name": "Red Hat"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "exploit-intelligence-tech-preview/vulnerability-analysis-rhel9 as a component of Exploit Intelligence",
          "product_id": "exploit_intelligence:exploit-intelligence-tech-preview/vulnerability-analysis-rhel9"
        },
        "product_reference": "exploit-intelligence-tech-preview/vulnerability-analysis-rhel9",
        "relates_to_product_reference": "exploit_intelligence"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "ansible-automation-platform-26/lightspeed-chatbot-rhel9 as a component of Red Hat Ansible Automation Platform 2",
          "product_id": "red_hat_ansible_automation_platform_2:ansible-automation-platform-26/lightspeed-chatbot-rhel9"
        },
        "product_reference": "ansible-automation-platform-26/lightspeed-chatbot-rhel9",
        "relates_to_product_reference": "red_hat_ansible_automation_platform_2"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rhoai/odh-llama-stack-core-rhel9 as a component of Red Hat OpenShift AI (RHOAI)",
          "product_id": "red_hat_openshift_ai_(rhoai):rhoai/odh-llama-stack-core-rhel9"
        },
        "product_reference": "rhoai/odh-llama-stack-core-rhel9",
        "relates_to_product_reference": "red_hat_openshift_ai_(rhoai)"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2026-42203",
      "cwe": {
        "id": "CWE-94",
        "name": "Improper Control of Generation of Code ('Code Injection')"
      },
      "discovery_date": "2026-05-08T04:01:50.142391+00:00",
      "flags": [
        {
          "label": "vulnerable_code_not_present",
          "product_ids": [
            "exploit_intelligence:exploit-intelligence-tech-preview/vulnerability-analysis-rhel9",
            "red_hat_openshift_ai_(rhoai):rhoai/odh-llama-stack-core-rhel9"
          ]
        }
      ],
      "ids": [
        {
          "system_name": "Red Hat Bugzilla ID",
          "text": "2467917"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "A flaw was found in LiteLLM, an AI Gateway. An authenticated user could exploit this by sending a crafted prompt template to the POST /prompts/test endpoint. The endpoint rendered user-supplied prompt templates without proper sandboxing. This could lead to arbitrary code execution within the LiteLLM Proxy process, potentially exposing sensitive information such as API keys or database credentials, and allowing commands to be run on the host system.",
          "title": "Vulnerability description"
        },
        {
          "category": "summary",
          "text": "litellm: LiteLLM: Arbitrary code execution via unsandboxed prompt templates",
          "title": "Vulnerability summary"
        },
        {
          "category": "other",
          "text": "Important: This flaw in LiteLLM, an AI Gateway, allows an authenticated user to achieve arbitrary code execution by sending a crafted prompt template to the /prompts/test endpoint. This is considered Important due to the potential for exposure of sensitive information, such as API keys or database credentials, and the ability to run commands on the host system, impacting the integrity and confidentiality of the deployed environment.",
          "title": "Statement"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "known_affected": [
          "red_hat_ansible_automation_platform_2:ansible-automation-platform-26/lightspeed-chatbot-rhel9"
        ],
        "known_not_affected": [
          "exploit_intelligence:exploit-intelligence-tech-preview/vulnerability-analysis-rhel9",
          "red_hat_openshift_ai_(rhoai):rhoai/odh-llama-stack-core-rhel9"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://access.redhat.com/security/cve/CVE-2026-42203"
        },
        {
          "category": "external",
          "summary": "RHBZ#2467917",
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2467917"
        },
        {
          "category": "external",
          "summary": "https://www.cve.org/CVERecord?id=CVE-2026-42203",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-42203"
        },
        {
          "category": "external",
          "summary": "https://nvd.nist.gov/vuln/detail/CVE-2026-42203",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42203"
        },
        {
          "category": "external",
          "summary": "https://github.com/BerriAI/litellm/releases/tag/v1.83.7-stable",
          "url": "https://github.com/BerriAI/litellm/releases/tag/v1.83.7-stable"
        },
        {
          "category": "external",
          "summary": "https://github.com/BerriAI/litellm/security/advisories/GHSA-xqmj-j6mv-4862",
          "url": "https://github.com/BerriAI/litellm/security/advisories/GHSA-xqmj-j6mv-4862"
        }
      ],
      "release_date": "2026-05-08T03:36:58.648000+00:00",
      "remediations": [
        {
          "category": "workaround",
          "details": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.",
          "product_ids": [
            "red_hat_ansible_automation_platform_2:ansible-automation-platform-26/lightspeed-chatbot-rhel9"
          ]
        },
        {
          "category": "none_available",
          "details": "Affected",
          "product_ids": [
            "red_hat_ansible_automation_platform_2:ansible-automation-platform-26/lightspeed-chatbot-rhel9"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 8.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "exploit_intelligence:exploit-intelligence-tech-preview/vulnerability-analysis-rhel9",
            "red_hat_ansible_automation_platform_2:ansible-automation-platform-26/lightspeed-chatbot-rhel9",
            "red_hat_openshift_ai_(rhoai):rhoai/odh-llama-stack-core-rhel9"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important",
          "product_ids": [
            "exploit_intelligence:exploit-intelligence-tech-preview/vulnerability-analysis-rhel9",
            "red_hat_ansible_automation_platform_2:ansible-automation-platform-26/lightspeed-chatbot-rhel9",
            "red_hat_openshift_ai_(rhoai):rhoai/odh-llama-stack-core-rhel9"
          ]
        }
      ],
      "title": "litellm: LiteLLM: Arbitrary code execution via unsandboxed prompt templates"
    }
  ]
}