Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-59821

Опубликовано: 08 июл. 2026
Источник: nvd
CVSS3: 7.2
EPSS Низкий

Описание

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.82.0-stable, LiteLLM's Custom Code Guardrails production create and update paths did not apply the same sandboxing and validation used by the test endpoint, allowing a privileged user with access to create or update guardrails to submit custom Python code that executed in the LiteLLM proxy environment and could expose secrets available to the process. This issue is fixed in version 1.82.0-stable.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:litellm:litellm:*:*:*:*:*:*:*:*
Версия до 1.82.0 (исключая)
cpe:2.3:a:litellm:litellm:1.82.0:nightly:*:*:*:*:*:*

EPSS

Процентиль: 28%
0.00355
Низкий

7.2 High

CVSS3

Дефекты

CWE-94

Связанные уязвимости

CVSS3: 7.2
redhat
26 дней назад

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.82.0-stable, LiteLLM's Custom Code Guardrails production create and update paths did not apply the same sandboxing and validation used by the test endpoint, allowing a privileged user with access to create or update guardrails to submit custom Python code that executed in the LiteLLM proxy environment and could expose secrets available to the process. This issue is fixed in version 1.82.0-stable.

github
12 дней назад

LiteLLM: Custom Code Guardrails production endpoints bypass code safety checks

EPSS

Процентиль: 28%
0.00355
Низкий

7.2 High

CVSS3

Дефекты

CWE-94