CVE-2026-42208
Sfruttamento noto · CISA KEV
Data di correzione federale CISA 11 mag
Vulnerabilità ed exploit · Attacco ad app web
LiteLLM's proxy layer turns into a key vault breach when this flaw is hit. A pre-auth SQL injection in the API key verification path lets unauthenticated attackers read and modify the database that holds master keys, API keys, and other secrets. Patching closes the injection point, but it does not undo any credentials already exposed.
The issue is CVE-2026-42208. LiteLLM fixed it in version 1.83.7 by replacing string concatenation with parameterized queries. Reporting and vendor guidance say exploitation began about 36 hours after disclosure, and attackers were targeting tables with provider credentials, environment data, and configs rather than probing randomly.
For teams using LiteLLM as a shared gateway, the real risk is impersonation of downstream services after database access. Once those keys are taken, attackers can abuse connected LLM instances and other cloud services even if the gateway itself is later patched.
3 fonti · 29 apr
Sfruttamento noto · CISA KEV
Data di correzione federale CISA 11 mag
The Hacker News
LiteLLM CVE-2026-42208 SQL Injection Exploited within 36 Hours of Disclosure
CVE-2026-42208 exploited within 36 hours of disclosure, exposing LiteLLM credentials, risking cloud account compromise.
originaleSecurityWeek
Fresh LiteLLM Vulnerability Exploited Shortly After Disclosure
The vulnerability allows attackers to read data from a LiteLLM proxy’s database and potentially modify it.
originaleBleepingComputer
Hackers are exploiting a critical LiteLLM pre-auth SQLi flaw
Hackers are targeting sensitive information stored in the LiteLLM open-source large-language model (LLM) gateway by exploiting a critical vulnerability tracked as CVE-2026-42208.
originalePart of the PlainSec briefing for 2026-04-29
Every edition of this story: LiteLLM SQLi Exposes Keys Behind AI Gateways