CVE-2026-59821
HIGH EXPLOITEDLiteLLM: Custom Code Guardrails production endpoints bypass code safety checks
Title source: cnaExploitation Summary
CVE-2026-59821 has been observed exploited in the wild (reported by VulnCheck KEV).
Description
LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.82.0-stable, LiteLLM's Custom Code Guardrails production create and update paths did not apply the same sandboxing and validation used by the test endpoint, allowing a privileged user with access to create or update guardrails to submit custom Python code that executed in the LiteLLM proxy environment and could expose secrets available to the process. This issue is fixed in version 1.82.0-stable.
References (3)
Core 3
Core References
X_Refsource_Confirm x_refsource_confirm
https://github.com/BerriAI/litellm/security/advisories/GHSA-72m8-9m7m-h278
X_Refsource_Misc x_refsource_misc
https://github.com/BerriAI/litellm/commit/e50b4486d0f7aa0497185a1ebcdd2c91f1769eba
X_Refsource_Misc x_refsource_misc
https://github.com/BerriAI/litellm/releases/tag/v1.82.0-stable
Scores
CVSS v3
7.2
EPSS
0.0036
EPSS Percentile
28.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
VulnCheck KEV
2026-07-26
CWE
CWE-94
Status
published
Products (4)
BerriAI/litellm
< 1.82.0-stable
litellm/litellm
1.82.0 nightly
litellm/litellm
< 1.82.0
pypi/litellm
0 - 1.82.0PyPI
Published
Jul 08, 2026
Tracked Since
Jul 09, 2026