FixVibe

// code / spotlight

LiteLLM SQL Injection Advisory

A vulnerable LiteLLM Proxy version can turn API-key verification into database exposure.

What it is

LiteLLM often sits in front of model providers, application databases, and customer-facing AI features. When the proxy dependency is in an affected version range, a bug in API-key verification can move from package hygiene into authentication bypass and database exposure risk.

How it happens

CVE-2026-42208 is a SQL injection in LiteLLM Proxy's API-key verification that affects releases 1.81.16 through 1.83.6 and is fixed in 1.83.7. Because the flaw sits in the key check itself, a caller does not need a valid key to reach it: anyone who can reach an exposed proxy can.

What an attacker gets

A vulnerable LiteLLM Proxy can put API keys, proxy metadata, and backing database records at risk depending on how the service is deployed. The highest-risk case is an internet-exposed proxy used by a multi-tenant AI app.

// what fixvibe reports

What FixVibe reports

Runs when you connect a GitHub repository, on Pro and above. Each finding shows the file and line, its severity and fix steps you can paste into your AI coding tool.

How to fix it

Upgrade `litellm` to 1.83.7 or newer, regenerate the active lockfile, and deploy a fresh runtime image so an old wheel is not cached. If LiteLLM Proxy is exposed, review API-key verification assumptions, rotate credentials that may have been exposed, and keep auth tests around the proxy path.

// lance-le sur ta propre app

Continue de shipper pendant que FixVibe veille.

Connect a GitHub repo to check its code, dependencies and workflows.

Code source
198
tests dans cette catégorie
modules
155
vérifications code source dédiées
GitHub repos
190+
checks on each connected repo
Connect GitHub →

// checks récents · correctifs pratiques · shippe sereinement

LiteLLM SQL Injection Advisory: what it is and how to fix it · FixVibe