Critical LiteLLM SQL Injection Vulnerability Exploited in the Wild
ID: 042e9391-2e14-5559-83c1-e7c50be18a64
STIX ID: report--042e9391-2e14-5559-83c1-e7c50be18a64
Feed Name: Cyber Press
A critical pre-authentication SQL injection (CVE-2026-42208) in the LiteLLM gateway enables unauthenticated attackers to execute arbitrary SQL against backend databases; researchers observed active, targeted exploitation within 36 hours of public disclosure aiming to steal API/master keys, provider credentials, and configuration data. Administrators are urged to upgrade to LiteLLM v1.83.7, rotate credentials, audit logs, and restrict external access due to likely compromise of internet-exposed instances.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
