← volver
CVE-2026-59821lowexplotación observadaCWE-94

LiteLLM: Custom Code Guardrails production endpoints bypass code safety checks

30Vexday Risk Score

Prioriza la corrección. Ella explotación observada por VulnCheck.

ssvc Attendcvss 2.1epss 0.4%
de la publicación al arma
Publicada en NVD8 jul
VulnCheck+18d
probabilidad de explotación
0.4%top 72% de las CVE
explotación observada
VulnCheck
LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.82.0-stable, LiteLLM's Custom Code Guardrails production create and update paths did not apply the same sandboxing and validation used by the test endpoint, allowing a privileged user with access to create or update guardrails to submit custom Python code that executed in the LiteLLM proxy environment and could expose secrets available to the process. This issue is fixed in version 1.82.0-stable.
CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
Productos afectados
BerriAI · litellm