Disclosure summary
### Impact A database query used during proxy API key checks mixed the caller-supplied key value into the query text instead of passing it as a separate parameter. An unauthenticated attacker could send a specially crafted `Authorization` header to any LLM API route (for example `POST /chat/completions`) and reach this query through the proxy's error-handling path. An attacker could read data from the proxy's database and may be able to modify it, leading to unauthorised access to the proxy and the credentials it manages. ### Patches Fixed in **`1.83.7`**. The caller-supplied value is now always passed to the database as a separate parameter. Upgrade to `1.83.7` or later. ### Workarounds If upgrading is not immediately possible, set `disable_error_logs: true` under `general_settings`. This removes the path through which unauthenticated input reaches the vulnerable query. ### References - Patched release: [`v1.83.7-stable`](https://github.com/BerriAI/litellm/releases/tag/v1.83.7-stable) **Discovery Credit**: Tencent YunDing Security Lab
CISA remediation guidance
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
GitHub Reviewed Security Advisories · GHSA-r75f-5x8p-qvmc
Open original source · Updated Oct 05, 2026
LiteLLM has SQL Injection in Proxy API key verification
Source severity: CRITICAL / 9.3
| Ecosystem | Package | Affected range | First patched |
|---|---|---|---|
| pip | litellm | >= 1.81.16, < 1.83.7 | 1.83.7 |
Original records & references
- NIST NVD record
- CVE Program record
- CISA KEV catalog entry
- github.com — Reviewed advisory
PUBLISHED 2026-04-24T12:17:07-04:00
MODIFIED 2026-10-05T14:39:55-04:00
INGESTED 2026-10-06T11:45:33-04:00