EXECUTIVE SUMMARY:
CVE-2026-40217 with a CVSS score of 7.5 is a sandbox escape vulnerability in LiteLLM, affecting versions prior to 1.83.11, specifically the POST /guardrails/test_custom_code endpoint that runs user-supplied Python inside a hand-rolled sandbox. This sandbox can be escaped using bytecode-level techniques, allowing arbitrary code execution in the proxy process, which runs as root in the default Docker image. An attacker with a proxy-admin credential in default configurations can reach the endpoint, requiring a relatively high level of privileges to exploit this vulnerability. By escaping the sandbox, an attacker gains the ability to execute arbitrary code, leading to potentially severe business impact and consequences if exploited, including unauthorized access to sensitive data and system compromise. Prerequisites for exploitation include a proxy-admin credential and access to the affected endpoint.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY:
CVE-2026-40217 with a CVSS score of 7.5 is a sandbox escape vulnerability in LiteLLM, affecting versions prior to 1.83.11, specifically the POST /guardrails/test_custom_code endpoint that runs user-supplied Python inside a hand-rolled sandbox. This sandbox can be escaped using bytecode-level techniques, allowing arbitrary code execution in the proxy process, which runs as root in the default Docker image. An attacker with a proxy-admin credential in default configurations can reach the endpoint, requiring a relatively high level of privileges to exploit this vulnerability. By escaping the sandbox, an attacker gains the ability to execute arbitrary code, leading to potentially severe business impact and consequences if exploited, including unauthorized access to sensitive data and system compromise. Prerequisites for exploitation include a proxy-admin credential and access to the affected endpoint.[emaillocker id="1283"]
RECOMMENDATION:
REFERENCES:
The following reports contain further technical details:
https://github.com/advisories/GHSA-wxxx-gvqv-xp7p