CVE-2026-45758 Details
Description
Guardrails AI is a Python framework that helps build AI applications. On May 11, 2026 at approximately 6:00 PM Pacific, an attacker published a malicious version of `guardrails-ai` (0.10.1) to PyPI. Aany user who installed `guardrails-ai==0.10.1` from PyPI on May 11, 2026 may be affected. Security researchers identified the malicious package within approximately 2 hours of publication, and PyPI quarantined the repository. Based on our telemetry, Guardrails AI maintainers have observed no requests to Guardrails AI infrastructure originating from the malicious 0.10.1 version, and a review of system and access logs has produced no evidence of user data exfiltration through their systems. Users should upgrade to version 0.10.2 or downgrade to version 0.10.0, both of which are unaffected. Those who installed version 0.10.1 should rotate any credentials accessible from their machine (GitHub PATs, cloud provider keys, package registry tokens, API keys) and audit their GitHub account for unauthorized workflows or repositories.
A supply chain vulnerability has been identified in the Guardrails AI Python framework, specifically in version 0.10.1, which was maliciously published to PyPI on May 11, 2026. This compromised version contains code that, upon import, downloads and executes a remote payload on Linux systems. The malicious package was available for approximately two hours before being quarantined by PyPI. Users who installed this version may have compromised their local environment, although no evidence of user data exfiltration through Guardrails AI's systems has been found. The vulnerability stems from an employee's GitHub Personal Access Token being compromised, which allowed an attacker to publish the malicious package using secrets extracted from GitHub Actions.
Users should uninstall the malicious version 0.10.1 and upgrade to version 0.10.2 or downgrade to version 0.10.0, both of which are unaffected. Those who installed version 0.10.1 should rotate any credentials accessible from their machine, such as GitHub Personal Access Tokens, cloud provider keys, package registry tokens, and API keys. Additionally, audit GitHub accounts for unauthorized workflows or repositories.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 8, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/guardrails-ai/guardrails/blob/main/SECURITY_ADVISORY.md | [email protected] | Vendor Advisory |
| https://github.com/guardrails-ai/guardrails/issues/1473 | [email protected] | Issue Tracking |
| https://github.com/guardrails-ai/guardrails/security/advisories/GHSA-xmpw-2vmm-p4p6 | [email protected] | MitigationVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-506 | Embedded Malicious Code | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| guardrailsai guardrails ai | 0.10.1 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 23, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 8, 2026 | Initial Analysis | [email protected] |
| Jun 5, 2026 | New CVE Received | [email protected] |