CVE-2026-42208:LiteLLM代理预认证SQL注入漏洞
bishopfox.com | 漏洞 | 严重 | 已在野利用 | CVE-2026-42208 | #active-exploitation | #ai-security | #vulnerability-research | #sql-injection | #pre-auth | #litellm | #cve-2026-42208 | #ai-gateway
摘要
CVE-2026-42208——LiteLLM 代理 1.81.16 至 1.83.6 的预认证 SQL 注入:缺失参数绑定使任意 LLM 路由可注入 SQL(经 pg_sleep 时间盲注确认),披露约 36 小时后出现野外利用,需升级至 1.83.7。
- CVSS
- 9.8
- 发布时间
- 收录时间
Skip to content