High severity7.2NVD Advisory· Published Jul 8, 2026· Updated Jul 13, 2026
CVE-2026-59821
CVE-2026-59821
Description
LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.82.0-stable, LiteLLM's Custom Code Guardrails production create and update paths did not apply the same sandboxing and validation used by the test endpoint, allowing a privileged user with access to create or update guardrails to submit custom Python code that executed in the LiteLLM proxy environment and could expose secrets available to the process. This issue is fixed in version 1.82.0-stable.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
litellmPyPI | < 1.82.0 | 1.82.0 |
Affected products
3Patches
Vulnerability mechanics
References
5- github.com/BerriAI/litellm/commit/e50b4486d0f7aa0497185a1ebcdd2c91f1769ebanvdPatchWEB
- github.com/BerriAI/litellm/security/advisories/GHSA-72m8-9m7m-h278nvdMitigationPatchVendor AdvisoryWEB
- github.com/advisories/GHSA-72m8-9m7m-h278ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-59821ghsaADVISORY
- github.com/BerriAI/litellm/releases/tag/v1.82.0-stablenvdProductRelease NotesWEB
News mentions
1- Litellm: Batch of Three Vulnerabilities Includes RCE and Directory TraversalVypr Intelligence · Jul 8, 2026