The POST /guardrails/test_custom_code endpoint runs user-supplied Python inside a hand-rolled sandbox. The sandbox can be escaped using bytecode-level techniques, allowing arbitrary code execution in the proxy process — which runs as root in the default Docker image.
Reaching the endpoint requires a proxy-admin credential in default configurations.
Fixed in 1.83.11. The hand-rolled sandbox has been replaced with RestrictedPython. Upgrade to 1.83.11 or later.
If upgrading is not immediately possible, block POST /guardrails/test_custom_code at your reverse proxy or API gateway.
v1.83.10-stable1.81.101.81.111.81.121.81.131.81.141.81.151.81.161.81.81.81.91.81.9.dev1+17 more1.83.10Exploitability
AV:NAC:HAT:NPR:HUI:NVulnerable System
VC:HVI:HVA:HSubsequent System
SC:NSI:NSA:NCVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N