LiteLLM Guardrail Tester Sandbox Escape to Root RCE
- AI Infrastructure
- System Compromise & RCE
- Credential & Identity Theft
Zenity Labs recorded 569 POST requests to LiteLLM's /guardrails/test_custom_code endpoint from April 15 through May 24, 2026. The activity combined guessed or empty master-key values with a custom Python guardrail, first using 520 identical capability probes and later using hand-crafted CVE-2026-40217 sandbox escapes. Captured payloads rebuilt forbidden Python names, recovered builtins through generator or coroutine internals, and split into two observed outcomes: serializing environment secrets into the HTTP response, or launching a shell command through subprocess.Popen. Zenity replayed both captured paths on LiteLLM 1.83.0 and confirmed secret return and command execution; it does not claim that every honeypot attempt compromised a real target.