Zafiyet İstihbaratı

CVE-2026-42208 — BerriAI LiteLLM SQL Injection Vulnerability

BerriAI LiteLLM contains a SQL injection vulnerability that allows an attacker to read data from the proxy's database and potentially modify it, leading to unauthorized access to the proxy and the credentials it manages.

CVECVE-2026-42208CVSSEPSSExploitCISA KEVVendorBerriAIÜrünLiteLLM

BerriAI LiteLLM contains a SQL injection vulnerability that allows an attacker to read data from the proxy's database and potentially modify it, leading to unauthorized access to the proxy and the credentials it manages.

CISA tarafından önerilen aksiyon

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Bu içerik yararlı oldu mu?Geri bildirim bu cihazda saklanır; varsayılan olarak sunucuya gönderilmez.