Bug 2498202 (CVE-2026-59821) - CVE-2026-59821 litellm: LiteLLM: Arbitrary code execution and information disclosure via custom code guardrails
Summary: CVE-2026-59821 litellm: LiteLLM: Arbitrary code execution and information dis...
Keywords:
Status: NEW
Alias: CVE-2026-59821
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-07-08 20:02 UTC by OSIDB Bzimport
Modified: 2026-07-09 15:05 UTC (History)
19 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-07-08 20:02:02 UTC
LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.82.0-stable, LiteLLM's Custom Code Guardrails production create and update paths did not apply the same sandboxing and validation used by the test endpoint, allowing a privileged user with access to create or update guardrails to submit custom Python code that executed in the LiteLLM proxy environment and could expose secrets available to the process. This issue is fixed in version 1.82.0-stable.


Note You need to log in before you can comment on or make changes to this bug.