logo

Critical LiteLLM SQL Injection Vulnerability Exploited in the Wild

ID: 042e9391-2e14-5559-83c1-e7c50be18a64

STIX ID: report--042e9391-2e14-5559-83c1-e7c50be18a64

Feed Name: Cyber Press

Threat Score
88/100

Date Published: 2026-04-28

Date Updated: 2026-04-28

Author: AnuPriya

...
...

A critical pre-authentication SQL injection (CVE-2026-42208) in the LiteLLM gateway enables unauthenticated attackers to execute arbitrary SQL against backend databases; researchers observed active, targeted exploitation within 36 hours of public disclosure aiming to steal API/master keys, provider credentials, and configuration data. Administrators are urged to upgrade to LiteLLM v1.83.7, rotate credentials, audit logs, and restrict external access due to likely compromise of internet-exposed instances.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.