Hackers are exploiting a critical LiteLLM pre-auth SQLi flaw
ID: 31104476-af95-5911-bd8a-da675a31dafa
STIX ID: report--31104476-af95-5911-bd8a-da675a31dafa
Feed Name: Bleeping Computer
A critical unauthenticated SQL injection (CVE-2026-42208) in the LiteLLM proxy enables attackers to exfiltrate API keys, provider credentials, and environment secrets by sending a crafted Authorization header to LLM API routes. A fix was issued in LiteLLM 1.83.7 (parameterized queries); researchers observed targeted exploitation beginning ~36 hours after public disclosure, and recommend upgrading, rotating exposed keys, or applying the suggested workaround (disable_error_logs:true) for unpatched instances.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
