Pre-Auth SQLi Flaw in LiteLLM Gateway Actively Exploited to Steal AI Credentials
A critical unauthenticated SQL injection vulnerability (CVE-2026-42208) in LiteLLM, a widely-used LLM proxy and SDK middleware, is being actively exploited to extract API keys, provider credentials, …
AML.T0040 - ML Model Inference API Access
AML.T0012 - Valid Accounts
AML.T0047 - ML-Enabled Product or Service