LiteLLM < 2026-04-08 - Remote Code Execution via Guardrails Test Custom Code Endpoint
Title source: llmExploitation Summary
CVE-2026-40217 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 2 public exploits from researchers including learner202649.
AI-analyzed exploit summary This repository contains a functional exploit for CVE-2026-40217, demonstrating a sandbox escape in LiteLLM's guardrail testing endpoint leading to remote code execution (RCE) as root in default Docker deployments. The exploit leverages CPython bytecode rewriting to bypass regex-based source code filtering.
Description
LiteLLM through 2026-04-08 allows remote attackers to execute arbitrary code via bytecode rewriting at the /guardrails/test_custom_code URI.
Exploits (2)
This repository contains a functional exploit for CVE-2026-40217, demonstrating a sandbox escape in LiteLLM's guardrail testing endpoint leading to remote code execution (RCE) as root in default Docker deployments. The exploit leverages CPython bytecode rewriting to bypass regex-based source code filtering.
This repository contains a functional exploit for CVE-2026-40217, a sandbox escape vulnerability in LiteLLM's guardrail mechanism. The exploit bypasses regex-based filtering by rewriting CPython bytecode to achieve arbitrary command execution via crafted custom_code payloads.
References (6)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H