Vulnerability Overview
A critical vulnerability identified as CVE-2026-65120 (CVSS v3.1 9.8) has been discovered in LiteLLM Proxy, the popular open-source AI gateway used by enterprises to manage, route, and load-balance calls across OpenAI, Anthropic, Bedrock, and Azure AI models. The vulnerability permits remote unauthenticated callers to execute arbitrary SQL commands against the underlying PostgreSQL/pgvector database via tainted metadata filter queries passed to vector retrieval endpoints.
Attack Mechanics & Code Breakdown
Enterprise deployments frequently configure LiteLLM Proxy to handle Retrieval-Augmented Generation (RAG) caching and semantic routing using an embedded vector store backend. When a client performs semantic search or document retrieval via POST /v1/embeddings/query, the service permits filtering results using dynamic metadata dictionaries.
Prior to version 1.52.4, the metadata query builder concatenated JSON keys directly into dynamic raw SQL query strings instead of using prepared statements or Prisma/SQLAlchemy parameterized bindings:
# Vulnerable raw SQL concatenation in LiteLLM vector query handler
query = f"""
SELECT doc_id, content, 1 - (embedding <=> '{vector}') AS similarity
FROM documents
WHERE tenant_id = '{tenant_id}' AND metadata->>'{filter_key}' = '{filter_val}'
"""
By injecting SQL metacharacters into the filter_key parameter (such as ' UNION SELECT null, secret_token, 1 FROM api_keys--), an attacker can extract plaintext upstream LLM API tokens, administrative gateway credentials, and proprietary prompt audit histories across all tenant boundaries.
Impact & Blast Radius
Because LiteLLM Proxy is typically deployed as a centralized hub holding credentials for enterprise cloud providers (AWS Bedrock keys, Azure OpenAI API secrets, and Claude workspace tokens), database compromise exposes all integrated cloud AI accounts to unauthorized draining and lateral data theft.
Defensive Playbook & Remediation
| Component | Vulnerable Version | Fixed Release | Action Required |
|---|---|---|---|
| LiteLLM Core Proxy | < 1.52.4 | 1.52.4 or later | Deploy container image update; verify parameterized queries |
| PostgreSQL Database | All unsegmented | Role restricted | Drop SUPERUSER rights; enforce read-only role on vector queries |
| API Token Storage | Plaintext columns | Vault / KMS encrypted | Enable database field-level encryption for provider secrets |



