Critical LiteLLM SQL Injection Vulnerability Exploited in the Wild
ID: 2bb67086-bad5-536e-ab32-c2ed3427f14c
STIX ID: report--2bb67086-bad5-536e-ab32-c2ed3427f14c
Feed Name: cybersecurityNews.com
A critical pre-authentication SQL injection (CVE-2026-42208) in the widely used LiteLLM AI gateway is being actively exploited to extract master API keys and cloud/provider credentials from its PostgreSQL database; attackers exploited an unprotected Authorization Bearer header (payload example sk-litellm’) to run arbitrary DB commands against sensitive tables, with evidence of rapid, targeted abuse (specific tables and two attacker IPs) and an upstream fix released in version 1.83.7—organizations must assume compromise for exposed instances, apply the patch, rotate keys, and monitor billing and logs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
