LiteLLM CVE-2026-42208 SQL Injection Exploited within 36 Hours
CVE-2026-42208, a CVSS 9.3 SQL injection flaw in BerriAI's LiteLLM, was publicly disclosed. Active exploitation began within 36 hours; attackers modified underlying data in affected LLM deployments. A 36-hour response window is, by industry standards, considered fast.
Severity: Unrated · Category: Prompt Injection
Impact: Modification of underlying data related to LLM operations
Source: The Hacker News · Apr 28 2026
How Fencio prevents this
The agent could not tell the difference between text it was reading and instructions it should follow. Once untrusted content reached its context window, it carried the same weight as the operator's own prompt, and the agent acted on it with every permission it had.
Fencio tags every span of context with where it came from. Instructions that arrive inside retrieved documents, tickets, emails, or tool output are treated as data, and any tool call they try to trigger is checked against the policy for untrusted content before it runs.