Skip to content

docs: correct LiteLLM version guidance (CVE-2026-42208) - #95

Open
sebastianomarchesini wants to merge 1 commit into
SAP-docs:mainfrom
sebastianomarchesini:patch-1
Open

sebastianomarchesini wants to merge 1 commit into
SAP-docs:mainfrom
sebastianomarchesini:patch-1

Conversation

@sebastianomarchesini

Copy link
Copy Markdown

The caution note stated that LiteLLM 1.82.6 and below are safe to install. 1.82.6 falls inside the affected range of CVE-2026-42208 (>= 1.81.16, < 1.83.7), a critical SQL injection in the LiteLLM proxy, so the page recommended a vulnerable release.

Also clarified that 1.82.7 and 1.82.8 were a supply chain compromise rather than ordinary vulnerabilities, and added the remediation that requires: rotating credentials reachable from that environment and removing any litellm_init.pth file.

The replacement text sets a floor of 1.83.7 and points to the current release rather than naming a single safe version.

Refs: GHSA-r75f-5x8p-qvmc
Refs: https://docs.litellm.ai/blog/security-update-march-2026

Updated caution note regarding LiteLLM versions due to vulnerabilities and provided guidance on safe versions.
Reference 1: GHSA-r75f-5x8p-qvmc
Reference 2: https://docs.litellm.ai/blog/security-update-march-2026
@cla-assistant

cla-assistant Bot commented Aug 23, 2026

Copy link
Copy Markdown

CLA assistant check
All committers have signed the CLA.

@karu-0711 karu-0711 added contribution Valuable Contribution type/clarity Something was unclear in the documentation. follow-up-with/dev Clarification with development needed. labels Sep 17, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

contribution Valuable Contribution follow-up-with/dev Clarification with development needed. type/clarity Something was unclear in the documentation.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants