PyPI: guardrails-ai

CVE-2026-45758

Safety vulnerability ID: SFTY-20260519-77196

Safety legacy ID: pyup.io-98484

Affected versions of the guardrails-ai package are vulnerable to Embedded Malicious Code due to a supply-chain compromise in which an unauthorised party published a tampered release to PyPI. Version 0.10.1 of guardrails-ai was uploaded to PyPI as a malicious build that diverges from the legitimate upstream guardrails-ai source tree and contains code executed at install or import time, distinct from any sanctioned release of the project. Any environment that installed guardrails-ai 0.10.1 from PyPI during the window between publication and PyPI quarantine should be treated as compromised, as the embedded payload can perform arbitrary actions on the host with the privileges of the installing or importing process, including credential theft and onward lateral movement.

Created at: Jun 8, 2026Updated at: Jun 8, 2026

Overview

Malicious code in guardrails-ai 0.10.1 (supply chain compromise)

Advisory

Affected versions of the guardrails-ai package are vulnerable to Embedded Malicious Code due to a supply-chain compromise in which an unauthorised party published a tampered release to PyPI. Version 0.10.1 of guardrails-ai was uploaded to PyPI as a malicious build that diverges from the legitimate upstream guardrails-ai source tree and contains code executed at install or import time, distinct from any sanctioned release of the project. Any environment that installed guardrails-ai 0.10.1 from PyPI during the window between publication and PyPI quarantine should be treated as compromised, as the embedded payload can perform arbitrary actions on the host with the privileges of the installing or importing process, including credential theft and onward lateral movement.

Affected Package

Affecting guardrails-ai package, versions
==0.10.1

Also affects

---

How to Fix

Upgrade
guardrails-ai
to
0.10.2
or higher.

Mitigation and Workarounds

---

Vulnerable Functions

Functions linked to known vulnerabilities.

Vulnerable function data is available for Enterprise customers

Book a call with us to see Safety in action.

Safety

Verified by Safety

Our Cybersecurity Intelligence Team reviewed this vulnerability. We combine public data with our own research to find issues not yet reported to public sources.

Learn more