Project Subscriptions
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-xmpw-2vmm-p4p6 | Malicious code in guardrails-ai 0.10.1 (supply chain compromise) |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Mon, 08 Jun 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 08 Jun 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Guardrailsai guardrails Ai
|
|
| CPEs | cpe:2.3:a:guardrailsai:guardrails_ai:0.10.1:*:*:*:*:python:*:* | |
| Vendors & Products |
Guardrailsai guardrails Ai
|
Fri, 05 Jun 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Guardrailsai
Guardrailsai guardrails |
|
| Vendors & Products |
Guardrailsai
Guardrailsai guardrails |
Fri, 05 Jun 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Guardrails AI is a Python framework that helps build AI applications. On May 11, 2026 at approximately 6:00 PM Pacific, an attacker published a malicious version of `guardrails-ai` (0.10.1) to PyPI. Aany user who installed `guardrails-ai==0.10.1` from PyPI on May 11, 2026 may be affected. Security researchers identified the malicious package within approximately 2 hours of publication, and PyPI quarantined the repository. Based on our telemetry, Guardrails AI maintainers have observed no requests to Guardrails AI infrastructure originating from the malicious 0.10.1 version, and a review of system and access logs has produced no evidence of user data exfiltration through their systems. Users should upgrade to version 0.10.2 or downgrade to version 0.10.0, both of which are unaffected. Those who installed version 0.10.1 should rotate any credentials accessible from their machine (GitHub PATs, cloud provider keys, package registry tokens, API keys) and audit their GitHub account for unauthorized workflows or repositories. | |
| Title | Malicious code in guardrails-ai 0.10.1 (supply chain compromise) | |
| Weaknesses | CWE-506 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-06-08T16:21:05.870Z
Reserved: 2026-05-13T06:54:34.222Z
Link: CVE-2026-45758
Updated: 2026-06-08T16:21:00.943Z
Status : Analyzed
Published: 2026-06-05T20:17:32.357
Modified: 2026-06-08T15:22:49.137
Link: CVE-2026-45758
No data.
OpenCVE Enrichment
Updated: 2026-06-05T21:45:05Z
Github GHSA