Malicious Package Incident in Guardrails AI Framework by Guardrails AI
CVE-2026-45758

9.6CRITICAL

Key Information:

Vendor
CVE Published:
5 June 2026

What is CVE-2026-45758?

On May 11, 2026, a malicious version of the Guardrails AI framework package, guardrails-ai==0.10.1, was published to Python Package Index (PyPI). Users who installed this version are advised to upgrade to guardrails-ai 0.10.2 or revert to guardrails-ai 0.10.0, which are safe from exploitation. Although no unauthorized access to user data has been reported, users should rotate any credentials stored locally and review their GitHub accounts for unusual activities. Prompt action is crucial to mitigate potential risks.

Affected Version(s)

guardrails = 0.10.1

References

CVSS V3.1

Score:
9.6
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.