LiteLLM's AI Gateway Shipped a Critical SQL Injection and a Command Injection in the Same Patch Cycle
An unauthenticated SQL injection in API key checks and an authenticated command injection via MCP preview endpoints both hit BerriAI's LiteLLM proxy, fixed together in v1.83.7.