Warning: LiteLLM pre-auth SQL injection (CVE-2026-42208), Patch Immediately!
ID: 6bef161e-40ed-5e92-ab1f-cb97eac2fb6e
STIX ID: report--6bef161e-40ed-5e92-ab1f-cb97eac2fb6e
Feed Name: CCB Advisories Feed
LiteLLM contains a critical pre-authentication SQL injection (CVE-2026-42208, CVSS 9.3) that allows unauthenticated attackers to exfiltrate stored API keys and provider credentials across connected AI providers; active exploitation has been observed and CISA added the flaw to its Known Exploited Vulnerabilities catalog. Centre for Cybersecurity Belgium recommends immediate patching to v1.83.7, applying the provided mitigation (disable_error_logs:true) if patching is delayed, and enhancing detection and incident reporting procedures.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
