PT-2026-56544 · Litellm · Litellm

·

CVE-2026-59821

·

Published

2026-07-08

·

Updated

2026-09-11

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions LiteLLM versions prior to 1.82.0-stable
Description LiteLLM is a proxy server that acts as an AI Gateway for calling LLM APIs. A flaw exists in the production create and update paths of the Custom Code Guardrails, which failed to apply the same sandboxing and validation used by the test endpoint. This allows a privileged user with permissions to create or update guardrails to submit custom Python code that executes within the LiteLLM proxy environment, potentially exposing secrets available to the process. This issue has been exploited in real-world incidents.
Recommendations Update to version 1.82.0-stable.

Exploit

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-59821
ECHO-4543-9144-2CC5
GHSA-72M8-9M7M-H278
PYSEC-2026-3478

Affected Products

Litellm