Known CVE
LiteLLM - SQL Injection
LiteLLM 1.81.16 to < 1.83.7 contains a SQL injection caused by improper handling of caller-supplied key in database query during proxy API key checks, letting unauthenticated attackers read and modify database data, exploit requires crafted Authorization header.
CVE-2026-42208
Critical2026CVSS 9.8CWE-89
cve2026 · litellm · sqli · unauthenticated · kev · vkev
Verified scans run this check after you prove you own the site.
All known CVEsView the checks catalogNational Vulnerability Database
Scan a website