Skip to content
LiteLLMGHSA-wxxx-gvqv-xp7p

LiteLLM has a sandbox escape in custom-code guardrail

High8.8CVE-2026-40217 · Published May 11, 2026 · updated Sep 10, 2026

### Impact The `POST /guardrails/test_custom_code` endpoint runs user-supplied Python inside a hand-rolled sandbox. The sandbox can be escaped using bytecode-level techniques, allowing arbitrary code execution in the proxy process , which runs as root in the default Docker image. **Reaching the endpoint requires a proxy-admin credential** in default configurations. ### Patches Fixed in **`1.83.11`**. The hand-rolled sandbox has been replaced with `RestrictedPython`. Upgrade to `1.83.11` or later. ### Workarounds If upgrading is not immediately possible, block `POST /guardrails/test_custom_code` at your reverse proxy or API gateway. ### References - Patched release: [`v1.83.10-stable`](https://github.com/BerriAI/litellm/releases/tag/v1.83.10-stable)

GitHub advisory

Affected versions

PackageAffectedFixed in
litellm
PyPI
>= 1.81.8, < 1.83.101.83.10
Details and references

More LiteLLM advisories

All LiteLLM

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.