CRITICALCVSS 9.8Vulnerability

CVE-2026-42208

BerriAI LiteLLM contains a SQL injection vulnerability that allows an attacker to read data from the proxy's database and potentially modify it, leading to unauthorized access to the proxy and the credentials it manages.

Properties

severity
CRITICAL
product
LiteLLM
vulnerabilityName
BerriAI LiteLLM SQL Injection Vulnerability
cvss_score
9.8
epss_score
0.8942
dueDate
2026-05-11
requiredAction
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
dateAdded
2026-05-08
cve_id
CVE-2026-42208
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vendorProject
BerriAI
epss_percentile
0.99771

Related Entities (4)

MENTIONED_IN (1)

[Campaign]How attackers are jailbreaking LLMs with CTF framing and how to catch them

DESCRIBES (1)

[KEVEntry]BerriAI LiteLLM SQL Injection Vulnerability

ENRICHED_BY (1)

[Source]FIRST EPSS

KNOWN_EXPLOITED (1)

[Source]CISA KEV

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-42208 (CVSS 9.8) — Ninja Signal Threat Intelligence | Ninja Signal