FixVibe

// код / прожектор

LiteLLM SQL Injection Advisory

A vulnerable LiteLLM Proxy version can turn API-key verification into database exposure.

What it is

LiteLLM often sits in front of model providers, application databases, and customer-facing AI features. When the proxy dependency is in an affected version range, a bug in API-key verification can move from package hygiene into authentication bypass and database exposure risk.

How it happens

CVE-2026-42208 is a SQL injection in LiteLLM Proxy's API-key verification that affects releases 1.81.16 through 1.83.6 and is fixed in 1.83.7. Because the flaw sits in the key check itself, a caller does not need a valid key to reach it: anyone who can reach an exposed proxy can.

What an attacker gets

A vulnerable LiteLLM Proxy can put API keys, proxy metadata, and backing database records at risk depending on how the service is deployed. The highest-risk case is an internet-exposed proxy used by a multi-tenant AI app.

// what fixvibe reports

What FixVibe reports

Runs when you connect a GitHub repository, on Pro and above. Each finding shows the file and line, its severity and fix steps you can paste into your AI coding tool.

How to fix it

Upgrade `litellm` to 1.83.7 or newer, regenerate the active lockfile, and deploy a fresh runtime image so an old wheel is not cached. If LiteLLM Proxy is exposed, review API-key verification assumptions, rotate credentials that may have been exposed, and keep auth tests around the proxy path.

// запусти на своём приложении

Продолжай выпускать продукт, пока FixVibe следит за рисками.

Connect a GitHub repo to check its code, dependencies and workflows.

Исходный код
198
тестов в этой категории
модулей
155
проверок исходный код
GitHub repos
190+
checks on each connected repo
Connect GitHub →

// актуальные проверки · практичные фиксы · выпускай увереннее

LiteLLM SQL Injection Advisory: what it is and how to fix it · FixVibe