PT-2026-59255 · Pypi · Litellm
Publicado
2026-07-13
·
Atualizado
2026-07-13
CVSS v3.1
8.8
Alta
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Impact
The
POST /guardrails/test custom code endpoint runs user-supplied Python inside a hand-rolled sandbox. The sandbox can be escaped using bytecode-level techniques, allowing arbitrary code execution in the proxy process — which runs as root in the default Docker image.Reaching the endpoint requires a proxy-admin credential in default configurations.
Patches
Fixed in
1.83.11. The hand-rolled sandbox has been replaced with RestrictedPython. Upgrade to 1.83.11 or later.Workarounds
If upgrading is not immediately possible, block
POST /guardrails/test custom code at your reverse proxy or API gateway.References
- Patched release:
v1.83.10-stable
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Litellm