Junglewise Threat Intelligence

CVE-2026-31233: Guardrails AI code injection in Hub package installation

CVE-2026-31233 · Severity: critical · CVSS 9.8 · Published 2026-05-12

Technologies: guardrails-ai (PyPI). Vendors: PyPI.

Executive brief

Guardrails AI, a tool used to ensure safety and reliability in Large Language Model (LLM) outputs, contains a critical security flaw in its package installation system. An attacker could publish a malicious package to the Guardrails Hub that, when installed by a user, automatically runs harmful code on the user's computer. This could lead to a total system takeover, theft of sensitive data, or disruption of business operations.

Technical details

A code injection vulnerability (CWE-94) exists in the Guardrails AI Hub package installation mechanism. When a user executes the 'guardrails hub install' command, the system fetches a manifest from the Hub and dynamically executes a script defined in the 'post_install' field. Because the script path is constructed from untrusted manifest data without sufficient validation or sanitization, an attacker who successfully publishes a malicious package to the Hub can achieve remote code execution (RCE) on the victim's machine. The vulnerability is present in versions up to and including 0.6.7; as of the advisory date, no patched version is specified.

Affected products

  • Guardrails AI guardrails-ai <= 0.6.7

Timeline

  • 2026-05-12: disclosed
  • 2026-05-12: advisory: Published to GitHub Advisory Database and NVD
  • 2026-05-27: other: Advisory updated and reviewed by GitHub

References

Related threats