{"id":"GHSA-3926-2jvf-fg29","summary":"Duplicate Advisory: LiteLLM has a sandbox escape in custom-code guardrail","details":"### Duplicate Advisory\nThis advisory has been withdrawn because it is a duplicate of GHSA-wxxx-gvqv-xp7p. This link is maintained to preserve external references.\n\n### Original Description\nLiteLLM through 2026-04-08 allows remote attackers to execute arbitrary code via bytecode rewriting at the /guardrails/test_custom_code URI.","modified":"2026-09-10T03:50:42.400448144Z","published":"2026-04-10T15:31:57Z","withdrawn":"2026-05-11T16:17:14Z","database_specific":{"cwe_ids":["CWE-420"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2026-05-11T16:17:14Z","nvd_published_at":"2026-04-10T14:16:36Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-40217"},{"type":"WEB","url":"https://www.x41-dsec.de/lab/advisories/x41-2026-001-litellm"}],"affected":[{"package":{"name":"litellm","ecosystem":"PyPI","purl":"pkg:pypi/litellm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.81.8"},{"fixed":"1.83.10"}]}],"versions":["1.81.10","1.81.11","1.81.12","1.81.13","1.81.14","1.81.15","1.81.16","1.81.8","1.81.9","1.81.9.dev1","1.82.0","1.82.1","1.82.2","1.82.3","1.82.4","1.82.5","1.82.6","1.83.0","1.83.1","1.83.2","1.83.3","1.83.4","1.83.5","1.83.6","1.83.7","1.83.8","1.83.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-3926-2jvf-fg29/GHSA-3926-2jvf-fg29.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}