CVE-2026-42208
BerriAI LiteLLM — BerriAI LiteLLM SQL Injection Vulnerability
Weakness-Klassen (CWE)
CWE-89Base
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
cwe.mitre.org →CWE-89Base
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
cwe.mitre.org →
Re-Analyse & Statuswechsel
Chronologie der NVD-Audit-Events für diese CVE — Reanalyses, CVSS-Updates, CPE-Diffs.
- Modified Analysis2026-06-29 17:18 UTC· nvd@nist.gov
- Reference Type: redhat-SADP: https://access.redhat.com/security/cve/CVE-2026-42208 Types: Third Party Advisory
- Reference Type: redhat-SADP: https://bugzilla.redhat.com/show_bug.cgi?id=2463965 Types: Mitigation, Third Party Advisory
- Reference Type: redhat-SADP: https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42208.json Types: Third Party Advisory
Beschreibung
BerriAI LiteLLM enthält eine SQL-Injection-Schwachstelle, die es einem Angreifer ermöglicht, Daten aus der Datenbank des Proxys zu lesen und möglicherweise zu ändern, was zu unbefugtem Zugriff auf den Proxy und die von ihm verwalteten Anmeldedaten führt.
Quelle: CISA_KEV
Öffentliche Exploit-Referenzen
Öffentliche Proof-of-Concepts und Detection-Templates für diese Schwachstelle. Die Reife reicht von gemeldeten PoCs über funktionsfähige Detection-Skripte bis hin zu vollständig waffenfähigen Exploit-Modulen. NEOSEC mirrort den Code intern für forensische Analysen; nach außen verlinken wir ausschließlich auf die Original-Quellen.
Quellen & Referenzen
- https://github.com/BerriAI/litellm/security/advisories/GHSA-r75f-5x8p-qvmcweb
- https://nvd.nist.gov/vuln/detail/CVE-2026-42208advisory
- https://github.com/BerriAI/litellmpackage
- https://github.com/BerriAI/litellm/releases/tag/v1.83.7-stableweb
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-42208web
- https://pypi.org/project/litellmpackage
- https://github.com/advisories/GHSA-r75f-5x8p-qvmcadvisory