CVE-2026-59821

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.82.0-stable, LiteLLM's Custom Code Guardrails production create and update paths did not apply the same sandboxing and validation used by the test endpoint, allowing a privileged user with access to create or update guardrails to submit custom Python code that executed in the LiteLLM proxy environment and could expose secrets available to the process. This issue is fixed in version 1.82.0-stable.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:litellm:litellm:*:*:*:*:*:*:*:*
cpe:2.3:a:litellm:litellm:1.82.0:nightly:*:*:*:*:*:*

History

13 Jul 2026, 13:46

Type Values Removed Values Added
References () https://github.com/BerriAI/litellm/commit/e50b4486d0f7aa0497185a1ebcdd2c91f1769eba - () https://github.com/BerriAI/litellm/commit/e50b4486d0f7aa0497185a1ebcdd2c91f1769eba - Patch
References () https://github.com/BerriAI/litellm/releases/tag/v1.82.0-stable - () https://github.com/BerriAI/litellm/releases/tag/v1.82.0-stable - Product, Release Notes
References () https://github.com/BerriAI/litellm/security/advisories/GHSA-72m8-9m7m-h278 - () https://github.com/BerriAI/litellm/security/advisories/GHSA-72m8-9m7m-h278 - Mitigation, Patch, Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.2
First Time Litellm
Litellm litellm
CPE cpe:2.3:a:litellm:litellm:1.82.0:nightly:*:*:*:*:*:*
cpe:2.3:a:litellm:litellm:*:*:*:*:*:*:*:*

08 Jul 2026, 20:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-08 20:16

Updated : 2026-07-13 13:46


NVD link : CVE-2026-59821

Mitre link : CVE-2026-59821

CVE.ORG link : CVE-2026-59821


JSON object : View

Products Affected

litellm

  • litellm
CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')