PT-2026-59255 · Pypi · Litellm
Published
2026-07-13
·
Updated
2026-07-13
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Impact
The
POST /guardrails/test custom code endpoint runs user-supplied Python inside a hand-rolled sandbox. The sandbox can be escaped using bytecode-level techniques, allowing arbitrary code execution in the proxy process — which runs as root in the default Docker image.Reaching the endpoint requires a proxy-admin credential in default configurations.
Patches
Fixed in
1.83.11. The hand-rolled sandbox has been replaced with RestrictedPython. Upgrade to 1.83.11 or later.Workarounds
If upgrading is not immediately possible, block
POST /guardrails/test custom code at your reverse proxy or API gateway.References
- Patched release:
v1.83.10-stable
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Litellm