TTPwire Vol. 1 · MITRE ATT&CK·Tagged

← All stories

Bishop Fox

CVE-2026-42208: Pre-Authentication SQL Injection in LiteLLM Proxy

10 hours ago · Read original ↗

ATT&CK techniques detected

3 predictions
T1190Exploit Public-Facing Application
71%
“cve - 2026 - 42208 : pre - authentication sql injection in litellm proxy tl ; dr bishop fox researchers reproduced and confirmed cve - 2026 - 42208, a critical pre - authentication sql injection in berriai ' s litellm proxy affecting versions 1. 81. 16 through 1. 83. 6. an attack…”
T1190Exploit Public-Facing Application
59%
“internal helper function reached through an exception path nobody thought of as a privileged context. the auth dispatcher ' s assert was clearly written as a defensive guard against this exact class of bug, but the guard ' s failure mode was an exception caught by a generic handl…”
T1190Exploit Public-Facing Application
57%
“sql had been in proxy / utils. py since at least v1. 81. 15. what changed in 1. 81. 16 was the addition of an unauthenticated path to reach it, and that path remained open until the fix was implemented in 1. 83. 7. the advisory ( ghsa - r75f - 5x8p - qvmc ) credits tencent yundin…”

Summary

Bishop Fox researchers confirmed a critical pre-authentication SQL injection in LiteLLM proxy affecting versions 1.81.16 through 1.83.6. Attackers can exploit it without credentials, and it blends into normal logs. In-the-wild exploitation was observed within 36 hours of the advisory going public.