Opening SecureFlowLiteLLM Guardrail Tester Sandbox Escape to Root RCE
Case summary & sources

AIDEFEND SecureFlow / SecureFlow Case Index

Zenity Labs aidefend-sf0007

LiteLLM Guardrail Tester Sandbox Escape to Root RCE

  • AI Infrastructure
  • System Compromise & RCE
  • Credential & Identity Theft

Zenity Labs recorded 569 POST requests to LiteLLM's /guardrails/test_custom_code endpoint from April 15 through May 24, 2026. The activity combined guessed or empty master-key values with a custom Python guardrail, first using 520 identical capability probes and later using hand-crafted CVE-2026-40217 sandbox escapes. Captured payloads rebuilt forbidden Python names, recovered builtins through generator or coroutine internals, and split into two observed outcomes: serializing environment secrets into the HTTP response, or launching a shell command through subprocess.Popen. Zenity replayed both captured paths on LiteLLM 1.83.0 and confirmed secret return and command execution; it does not claim that every honeypot attempt compromised a real target.

Mapped threat techniques

Source