SOURCE-LINKED INTELLIGENCE
GHSA-r75f-5x8p-qvmc: LiteLLM has SQL Injection in Proxy API key verification
### Impact A database query used during proxy API key checks mixed the caller-supplied key value into the query text instead of passing it as a separate parameter. An unauthenticated attacker could send a specially crafted `Authorization` header to any LLM API route (for example `POST /chat/completions`) and reach this query through the proxy's error-handling path. An attacker could read data from the proxy's database and may be able to modify it, leading to unauthorised access to the proxy and the credentials it manages. ### Patches Fixed in **`1.83.7`**. The caller-supplied value is now alwa
Read original source ↗ Open in workspace
- recordType
- vulnerability
- status
- active
- evidenceStatus
- reported
- region
- Global
Evidence & attribution
- OSV AI package advisories · 2026-04-24T16:17:07.000Z
- OSV AI package advisories · 2026-06-29T11:50:45.645Z
First collected: 2026-09-20T23:41:51.992Z. This is not the publication date.