LiteLLM CVE-2026-42208 SQL Injection Exploited within 36 Hours of Disclosure
ID: 21b6f21a-d01f-59a3-8f9d-5232416e58f9
STIX ID: report--21b6f21a-d01f-59a3-8f9d-5232416e58f9
Feed Name: The Hacker News
A critical SQL injection (CVE-2026-42208, CVSS 9.3) in the LiteLLM Python package allowed unauthenticated attackers to inject queries via the Authorization header and access/modify the proxy database; active exploitation was observed within ~26–36 hours of disclosure, with operators targeting credential and config tables (e.g., litellm_credentials.credential_values, litellm_config) from IPs 65.111.27.132 and 65.111.25.67. The flaw risks large-scale cloud-account compromise because rows often contain high-privilege keys (OpenAI, Anthropic, AWS Bedrock); maintainers released version 1.83.7-stable and advise either patching or setting disable_error_logs:true to mitigate exposure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
