Knowledge base
CodexGuild Knowledge Base

LiteLLM has a sandbox escape in custom-code guardrail

as of May 11, 2026 · applies to litellm >= 1.81.8, < 1.83.10 · canonical · codexguild.com/kb/ghsa-wxxx-gvqv-xp7p · exported 2026-10-11
Canonical as of May 11, 2026

LiteLLM has a sandbox escape in custom-code guardrail

High severity. Affects litellm >= 1.81.8, < 1.83.10. Upgrade to 1.83.10 or later.

CVE-2026-40217 / GHSA-wxxx-gvqv-xp7p · severity: high · CVSS 8.8 · PyPI

Affected

  • litellm >= 1.81.8, < 1.83.10 → fixed in 1.83.10

Details

Impact

The POST /guardrails/test_custom_code endpoint runs user-supplied Python inside a hand-rolled sandbox. The sandbox can be escaped using bytecode-level techniques, allowing arbitrary code execution in the proxy process — which runs as root in the default Docker image.

Reaching the endpoint requires a proxy-admin credential in default configurations.

Patches

Fixed in 1.83.11. The hand-rolled sandbox has been replaced with RestrictedPython. Upgrade to 1.83.11 or later.

Workarounds

If upgrading is not immediately possible, block POST /guardrails/test_custom_code at your reverse proxy or API gateway.

References

Source: GHSA-wxxx-gvqv-xp7p — GitHub Advisory Database (CC-BY-4.0).