Executive brief
Guardrails AI, a tool used to ensure safety and reliability in Large Language Model (LLM) outputs, contains a critical security flaw in its package installation system. An attacker could publish a malicious package to the Guardrails Hub that, when installed by a user, automatically runs harmful code on the user's computer. This could lead to a total system takeover, theft of sensitive data, or disruption of business operations.
Technical details
A code injection vulnerability (CWE-94) exists in the Guardrails AI Hub package installation mechanism. When a user executes the 'guardrails hub install' command, the system fetches a manifest from the Hub and dynamically executes a script defined in the 'post_install' field. Because the script path is constructed from untrusted manifest data without sufficient validation or sanitization, an attacker who successfully publishes a malicious package to the Hub can achieve remote code execution (RCE) on the victim's machine. The vulnerability is present in versions up to and including 0.6.7; as of the advisory date, no patched version is specified.
Affected products
- Guardrails AI guardrails-ai <= 0.6.7
Timeline
- 2026-05-12: disclosed
- 2026-05-12: advisory: Published to GitHub Advisory Database and NVD
- 2026-05-27: other: Advisory updated and reviewed by GitHub