VDB
Sign up
HIGH8.8

PYSEC-2026-2601

LiteLLM has a sandbox escape in custom-code guardrail

Quick fix

PYSEC-2026-2601 — litellm: upgrade to the fixed version with the command below.

pip install --upgrade 'litellm>=1.83.10'

Details

### Impact

The `POST /guardrails/test_custom_code` endpoint runs user-supplied Python inside a hand-rolled sandbox. The sandbox can be escaped using bytecode-level techniques, allowing arbitrary code execution in the proxy process — which runs as root in the default Docker image.

**Reaching the endpoint requires a proxy-admin credential** in default configurations.

### Patches

Fixed in **`1.83.11`**. The hand-rolled sandbox has been replaced with `RestrictedPython`. Upgrade to `1.83.11` or later.

### Workarounds

If upgrading is not immediately possible, block `POST /guardrails/test_custom_code` at your reverse proxy or API gateway.

### References

- Patched release: [`v1.83.10-stable`](https://github.com/BerriAI/litellm/releases/tag/v1.83.10-stable)

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/litellm
Introduced in: 1.81.8Fixed in: 1.83.10
Fixpip install --upgrade 'litellm>=1.83.10'

References