Close Menu
    What's Hot

    5 Things to Know About the Iowa Senate Candidate Josh Turek

    Messi trains alone as Argentina hold first World Cup practice | World Cup 2026 News

    Trump signs narrower executive order on AI oversight after industry objections 

    Facebook X (Twitter) Instagram
    Trending
    • 5 Things to Know About the Iowa Senate Candidate Josh Turek
    • Messi trains alone as Argentina hold first World Cup practice | World Cup 2026 News
    • Trump signs narrower executive order on AI oversight after industry objections 
    • Why Richard Nixon torpedoed the global monetary system
    • Nebius Stock And The Next Phase Of AI (NASDAQ:NBIS)
    • NBA Finals 2026: Experts’ picks for Knicks-Spurs, Finals MVP
    • Microsoft offers devs a better way to control AI agent behavior
    • Hegseth Shangri-La Remarks Fall Flat With Asian Audience
    interluknewsinterluknews
    • Home
    • Business
      • Corporate News
      • Industry Insights
      • Startups & Entrepreneurship
      • Technology & Innovation
    • Economy
      • Economic Policy
      • Financial Analysis
      • Inflation & Interest Rates
      • Trade & Markets
    • Global
      • Conflicts & Security
      • Diplomacy
      • Global Trends
      • International Affairs
    • Lifestyle
      • Fashion
      • Food & Dining
      • Personal Development
      • Travel
    • Opinion
      • Columns
      • Editorials
      • Expert Opinions
      • Reader Voices
    • More
      • Politics
        • Elections
        • Government & Policy
        • International Relations
        • Political Analysis
      • Sports
        • Cricket
        • Football / Soccer
        • International Sports
        • Local Sports
      • Technology
        • Artificial Intelligence
        • Cybersecurity
        • Gadgets & Reviews
        • Tech News
      • South Africa News
    Facebook X (Twitter) Instagram
    interluknewsinterluknews
    Cybersecurity

    LiteLLM CVE-2026-42208 SQL Injection Exploited within 36 Hours of Disclosure

    adminBy adminApril 29, 2026No Comments3 Mins Read
    Share Facebook Twitter Pinterest Copy Link Telegram LinkedIn Tumblr Email
    LiteLLM CVE-2026-42208 SQL Injection Exploited within 36 Hours of Disclosure
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ravie LakshmananApr 29, 2026Vulnerability / Cloud Security

    LiteLLM CVE-2026-42208 SQL Injection Exploited within 36 Hours of Disclosure

    In yet another instance of threat actors quickly jumping on the exploitation bandwagon, a newly disclosed critical security flaw in BerriAI’s LiteLLM Python package has come under active exploitation in the wild within 36 hours of the bug becoming public knowledge.

    The vulnerability, tracked as CVE-2026-42208 (CVSS score: 9.3), is an SQL injection that could be exploited to modify the underlying LiteLLM proxy database.

    “A database query used during proxy API key checks mixed the caller-supplied key value into the query text instead of passing it as a separate parameter,” LiteLLM maintainers said in an alert last week.

    Cybersecurity

    “An unauthenticated attacker could send a specially crafted Authorization header to any LLM API route (for example, POST /chat/completions) and reach this query through the proxy’s error-handling path. An attacker could read data from the proxy’s database and may be able to modify it, leading to unauthorized access to the proxy and the credentials it manages.”

    The shortcoming affects the following versions –

    While the vulnerability was addressed in version 1.83.7-stable released on April 19, 2026, the first exploitation attempt was recorded on April 26 at 16:17 UTC, roughly 26 hours and seven minutes after the GitHub advisory was indexed in the global GitHub Advisory Database. The SQL injection activity, per Sysdig, originated from the IP address 65.111.27[.]132.

    “Malicious activity fell into two phases driven by the same operator across two adjacent egress IPs, followed by a brief unauthenticated probe of the key-management endpoints,” security researcher Michael Clark said.

    Specifically, the unknown threat actor is said to have targeted database tables like “litellm_credentials.credential_values” and “litellm_config” that hold information related to upstream large language model (LLM) provider keys and the proxy runtime environment. No probes were observed against tables like “litellm_users” or “litellm_team.”

    This suggests that the attacker was not only aware of these tables, but also went after those that hold sensitive secrets. In the second phase of the attack, observed after 20 minutes, the threat actor used a different IP address (“65.111.25[.]67”), this time abusing the access to run a similar probe.

    LiteLLM is a popular, open-source AI Gateway software with over 45,000 stars and 7,600 forks on GitHub. Last month, the project was the target of a supply chain attack orchestrated by the TeamPCP hacking group to steal credentials and secrets from downstream users.

    “A single litellm_credentials row often holds an OpenAI organization key with five-figure monthly spend caps, an Anthropic console key with workspace admin rights, and an AWS Bedrock IAM credential,” Sysdig said. “The blast radius of a successful database extraction is closer to a cloud-account compromise than a typical web-app SQL injection.”

    Cybersecurity

    Users are advised to patch their instances to the latest version. If this is not an immediate option, the maintainers recommend setting “disable_error_logs: true” under “general_settings” to remove the path through which untrusted input reaches the vulnerable query.

    “The LiteLLM vulnerability (GHSA-r75f-5x8p-qvmc) continues the modal pattern for AI-infrastructure advisories: critical, pre-auth, and in software with five-figure star counts that operators trust to centralize cloud-grade credentials,” Sysdig added.

    “The 36-hour exploit window is consistent with the broader collapse documented by the Zero Day Clock, and the operator behavior we recorded (verbatim Prisma table names, three-table targeting, deliberate column-count enumeration) shows that exploitation no longer waits for a public PoC. The advisory and the open-source schema were ultimately enough.”

    CVE202642208 Disclosure Exploited hours Injection LiteLLM SQL
    Follow on Google News Follow on Flipboard
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
    Previous ArticleChina’s rural vitalisation strategy is reshaping the future of global development – The Mail & Guardian
    Next Article Snapchat is rolling out sponsored AI agents
    admin
    • Website

    Related Posts

    Oracle WebLogic CVE-2024-21182 Added to KEV Catalog After Active Exploitation

    June 2, 2026

    Google June 2026 Android Update Patches 124 Flaws, One Actively Exploited

    June 2, 2026

    Gamaredon Exploits WinRAR to Deliver GammaWorm and GammaSteel Against Ukraine

    June 2, 2026
    Leave A Reply Cancel Reply

    Demo
    Latest Posts

    5 Things to Know About the Iowa Senate Candidate Josh Turek

    Messi trains alone as Argentina hold first World Cup practice | World Cup 2026 News

    Trump signs narrower executive order on AI oversight after industry objections 

    Why Richard Nixon torpedoed the global monetary system

    Latest Posts

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    Advertisement
    Demo

    We are a digital news platform delivering timely, accurate, and insightful coverage of politics, global affairs, business, economy, sports, and more. Our mission is to keep readers informed with reliable news, clear analysis, and stories that truly matter.
    We're social. Connect with us:

    Facebook X (Twitter) Instagram Pinterest YouTube

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.

    Powered by
    ...
    ►
    Necessary cookies enable essential site features like secure log-ins and consent preference adjustments. They do not store personal data.
    None
    ►
    Functional cookies support features like content sharing on social media, collecting feedback, and enabling third-party tools.
    None
    ►
    Analytical cookies track visitor interactions, providing insights on metrics like visitor count, bounce rate, and traffic sources.
    None
    ►
    Advertisement cookies deliver personalized ads based on your previous visits and analyze the effectiveness of ad campaigns.
    None
    ►
    Unclassified cookies are cookies that we are in the process of classifying, together with the providers of individual cookies.
    None
    Powered by