logo

Warning: LiteLLM pre-auth SQL injection (CVE-2026-42208), Patch Immediately!

ID: 6bef161e-40ed-5e92-ab1f-cb97eac2fb6e

STIX ID: report--6bef161e-40ed-5e92-ab1f-cb97eac2fb6e

Feed Name: CCB Advisories Feed

Threat Score
93/100

Date Published: 2026-04-29

Date Updated: 2026-07-24

...
...

LiteLLM contains a critical pre-authentication SQL injection (CVE-2026-42208, CVSS 9.3) that allows unauthenticated attackers to exfiltrate stored API keys and provider credentials across connected AI providers; active exploitation has been observed and CISA added the flaw to its Known Exploited Vulnerabilities catalog. Centre for Cybersecurity Belgium recommends immediate patching to v1.83.7, applying the provided mitigation (disable_error_logs:true) if patching is delayed, and enhancing detection and incident reporting procedures.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.