LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.82.0-stable, LiteLLM's Custom Code Guardrails production create and update paths did not apply the same sandboxing and validation used by the test endpoint, allowing a privileged user with access to create or update guardrails to submit custom Python code that executed in the LiteLLM proxy environment and could expose secrets available to the process. This issue is fixed in version 1.82.0-stable.
References
| Link | Resource |
|---|---|
| https://github.com/BerriAI/litellm/commit/e50b4486d0f7aa0497185a1ebcdd2c91f1769eba | Patch |
| https://github.com/BerriAI/litellm/releases/tag/v1.82.0-stable | Product Release Notes |
| https://github.com/BerriAI/litellm/security/advisories/GHSA-72m8-9m7m-h278 | Mitigation Patch Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
13 Jul 2026, 13:46
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/BerriAI/litellm/commit/e50b4486d0f7aa0497185a1ebcdd2c91f1769eba - Patch | |
| References | () https://github.com/BerriAI/litellm/releases/tag/v1.82.0-stable - Product, Release Notes | |
| References | () https://github.com/BerriAI/litellm/security/advisories/GHSA-72m8-9m7m-h278 - Mitigation, Patch, Vendor Advisory | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.2 |
| First Time |
Litellm
Litellm litellm |
|
| CPE | cpe:2.3:a:litellm:litellm:1.82.0:nightly:*:*:*:*:*:* cpe:2.3:a:litellm:litellm:*:*:*:*:*:*:*:* |
08 Jul 2026, 20:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-07-08 20:16
Updated : 2026-07-13 13:46
NVD link : CVE-2026-59821
Mitre link : CVE-2026-59821
CVE.ORG link : CVE-2026-59821
JSON object : View
Products Affected
litellm
- litellm
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')
