Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wxxx-gvqv-xp7p

Опубликовано: 11 мая 2026
Источник: github
Github: Прошло ревью
CVSS4: 7.5
CVSS3: 8.8

Описание

LiteLLM has a sandbox escape in custom-code guardrail

Impact

The POST /guardrails/test_custom_code endpoint runs user-supplied Python inside a hand-rolled sandbox. The sandbox can be escaped using bytecode-level techniques, allowing arbitrary code execution in the proxy process — which runs as root in the default Docker image.

Reaching the endpoint requires a proxy-admin credential in default configurations.

Patches

Fixed in 1.83.11. The hand-rolled sandbox has been replaced with RestrictedPython. Upgrade to 1.83.11 or later.

Workarounds

If upgrading is not immediately possible, block POST /guardrails/test_custom_code at your reverse proxy or API gateway.

References

Пакеты

Наименование

litellm

pip
Затронутые версииВерсия исправления

>= 1.81.8, < 1.83.10

1.83.10

EPSS

Процентиль: 93%
0.06496
Низкий

7.5 High

CVSS4

8.8 High

CVSS3

Дефекты

CWE-420
CWE-913

Связанные уязвимости

CVSS3: 8.8
redhat
4 месяца назад

LiteLLM through 2026-04-08 allows remote attackers to execute arbitrary code via bytecode rewriting at the /guardrails/test_custom_code URI.

CVSS3: 8.8
nvd
4 месяца назад

LiteLLM through 2026-04-08 allows remote attackers to execute arbitrary code via bytecode rewriting at the /guardrails/test_custom_code URI.

CVSS3: 8.8
fstec
6 месяцев назад

Уязвимость прокси-сервера LiteLLM, связанная с использованием незащищенного альтернативного канала, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 93%
0.06496
Низкий

7.5 High

CVSS4

8.8 High

CVSS3

Дефекты

CWE-420
CWE-913