guardrails-ai
Adding guardrails to large language models.
Activity
- Latest release
- 1mo ago
- Total releases
- 106
- Cadence
- ~6 days
- Last 12 months
- 22
Details
- License
- Apache-2.0
- First release
- Mar 13, 2023
| Version | Released | |
|---|---|---|
0.11.0
minor
|
0.11.0
minor
Dependencies (55)
+ 47 more |
|
0.10.2
patch
|
0.10.2
patch
Dependencies (55)
+ 47 more |
|
0.10.0a5
pre
1 CVE
CVE-2026-45758
PYSEC-2026-206
GHSA-xmpw-2vmm-p4p6
Jun 05, 2026
9.6
/ 10
Critical
Network
Low
None
Required
Changed
High
High
High
Guardrails AI is a Python framework that helps build AI applications. On May 11, 2026 at approximately 6:00 PM Pacific, an attacker published a malicious version of Affected versions
0.1.0
0.1.0rc1
0.1.0rc2
0.1.0rc3
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
+ 92 more Show less
0.1.9
0.10.0
0.10.0a0
0.10.0a1
0.10.0a2
0.10.0a3
0.10.0a4
0.10.0a5
0.2.0
0.2.0a1
0.2.0a2
0.2.0a3
0.2.0a4
0.2.0a5
0.2.0a6
0.2.1
0.2.1a0
0.2.2
0.2.3
0.2.3a1
0.2.4
0.2.4a1
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.0a0
0.5.0a1
0.5.0a10
0.5.0a11
0.5.0a12
0.5.0a13
0.5.0a2
0.5.0a3
0.5.0a4
0.5.0a5
0.5.0a6
0.5.0a7
0.5.0a8
0.5.0a9
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.14
0.5.15
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.0a1
0.6.0a2
0.6.0a3
0.6.0a4
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
0.9.0rc0
0.9.1
0.9.2
0.9.3
References Updated Jun 09, 2026 · Source: OSV.dev |
0.10.0a5
pre
Dependencies (55)
+ 47 more |
|
0.10.0a4
pre
1 CVE
CVE-2026-45758
PYSEC-2026-206
GHSA-xmpw-2vmm-p4p6
Jun 05, 2026
9.6
/ 10
Critical
Network
Low
None
Required
Changed
High
High
High
Guardrails AI is a Python framework that helps build AI applications. On May 11, 2026 at approximately 6:00 PM Pacific, an attacker published a malicious version of Affected versions
0.1.0
0.1.0rc1
0.1.0rc2
0.1.0rc3
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
+ 92 more Show less
0.1.9
0.10.0
0.10.0a0
0.10.0a1
0.10.0a2
0.10.0a3
0.10.0a4
0.10.0a5
0.2.0
0.2.0a1
0.2.0a2
0.2.0a3
0.2.0a4
0.2.0a5
0.2.0a6
0.2.1
0.2.1a0
0.2.2
0.2.3
0.2.3a1
0.2.4
0.2.4a1
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.0a0
0.5.0a1
0.5.0a10
0.5.0a11
0.5.0a12
0.5.0a13
0.5.0a2
0.5.0a3
0.5.0a4
0.5.0a5
0.5.0a6
0.5.0a7
0.5.0a8
0.5.0a9
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.14
0.5.15
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.0a1
0.6.0a2
0.6.0a3
0.6.0a4
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
0.9.0rc0
0.9.1
0.9.2
0.9.3
References Updated Jun 09, 2026 · Source: OSV.dev |
0.10.0a4
pre
Dependencies (55)
+ 47 more |
|
0.10.0
minor
1 CVE
CVE-2026-45758
PYSEC-2026-206
GHSA-xmpw-2vmm-p4p6
Jun 05, 2026
9.6
/ 10
Critical
Network
Low
None
Required
Changed
High
High
High
Guardrails AI is a Python framework that helps build AI applications. On May 11, 2026 at approximately 6:00 PM Pacific, an attacker published a malicious version of Affected versions
0.1.0
0.1.0rc1
0.1.0rc2
0.1.0rc3
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
+ 92 more Show less
0.1.9
0.10.0
0.10.0a0
0.10.0a1
0.10.0a2
0.10.0a3
0.10.0a4
0.10.0a5
0.2.0
0.2.0a1
0.2.0a2
0.2.0a3
0.2.0a4
0.2.0a5
0.2.0a6
0.2.1
0.2.1a0
0.2.2
0.2.3
0.2.3a1
0.2.4
0.2.4a1
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.0a0
0.5.0a1
0.5.0a10
0.5.0a11
0.5.0a12
0.5.0a13
0.5.0a2
0.5.0a3
0.5.0a4
0.5.0a5
0.5.0a6
0.5.0a7
0.5.0a8
0.5.0a9
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.14
0.5.15
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.0a1
0.6.0a2
0.6.0a3
0.6.0a4
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
0.9.0rc0
0.9.1
0.9.2
0.9.3
References Updated Jun 09, 2026 · Source: OSV.dev |
0.10.0
minor
Dependencies (55)
+ 47 more |
|
0.9.3
patch
1 CVE
CVE-2026-45758
PYSEC-2026-206
GHSA-xmpw-2vmm-p4p6
Jun 05, 2026
9.6
/ 10
Critical
Network
Low
None
Required
Changed
High
High
High
Guardrails AI is a Python framework that helps build AI applications. On May 11, 2026 at approximately 6:00 PM Pacific, an attacker published a malicious version of Affected versions
0.1.0
0.1.0rc1
0.1.0rc2
0.1.0rc3
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
+ 92 more Show less
0.1.9
0.10.0
0.10.0a0
0.10.0a1
0.10.0a2
0.10.0a3
0.10.0a4
0.10.0a5
0.2.0
0.2.0a1
0.2.0a2
0.2.0a3
0.2.0a4
0.2.0a5
0.2.0a6
0.2.1
0.2.1a0
0.2.2
0.2.3
0.2.3a1
0.2.4
0.2.4a1
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.0a0
0.5.0a1
0.5.0a10
0.5.0a11
0.5.0a12
0.5.0a13
0.5.0a2
0.5.0a3
0.5.0a4
0.5.0a5
0.5.0a6
0.5.0a7
0.5.0a8
0.5.0a9
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.14
0.5.15
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.0a1
0.6.0a2
0.6.0a3
0.6.0a4
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
0.9.0rc0
0.9.1
0.9.2
0.9.3
References Updated Jun 09, 2026 · Source: OSV.dev |
0.9.3
patch
Dependencies (56)
+ 48 more |
|
0.10.0a3
pre
1 CVE
CVE-2026-45758
PYSEC-2026-206
GHSA-xmpw-2vmm-p4p6
Jun 05, 2026
9.6
/ 10
Critical
Network
Low
None
Required
Changed
High
High
High
Guardrails AI is a Python framework that helps build AI applications. On May 11, 2026 at approximately 6:00 PM Pacific, an attacker published a malicious version of Affected versions
0.1.0
0.1.0rc1
0.1.0rc2
0.1.0rc3
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
+ 92 more Show less
0.1.9
0.10.0
0.10.0a0
0.10.0a1
0.10.0a2
0.10.0a3
0.10.0a4
0.10.0a5
0.2.0
0.2.0a1
0.2.0a2
0.2.0a3
0.2.0a4
0.2.0a5
0.2.0a6
0.2.1
0.2.1a0
0.2.2
0.2.3
0.2.3a1
0.2.4
0.2.4a1
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.0a0
0.5.0a1
0.5.0a10
0.5.0a11
0.5.0a12
0.5.0a13
0.5.0a2
0.5.0a3
0.5.0a4
0.5.0a5
0.5.0a6
0.5.0a7
0.5.0a8
0.5.0a9
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.14
0.5.15
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.0a1
0.6.0a2
0.6.0a3
0.6.0a4
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
0.9.0rc0
0.9.1
0.9.2
0.9.3
References Updated Jun 09, 2026 · Source: OSV.dev |
0.10.0a3
pre
Dependencies (55)
+ 47 more |
|
0.10.0a2
pre
1 CVE
CVE-2026-45758
PYSEC-2026-206
GHSA-xmpw-2vmm-p4p6
Jun 05, 2026
9.6
/ 10
Critical
Network
Low
None
Required
Changed
High
High
High
Guardrails AI is a Python framework that helps build AI applications. On May 11, 2026 at approximately 6:00 PM Pacific, an attacker published a malicious version of Affected versions
0.1.0
0.1.0rc1
0.1.0rc2
0.1.0rc3
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
+ 92 more Show less
0.1.9
0.10.0
0.10.0a0
0.10.0a1
0.10.0a2
0.10.0a3
0.10.0a4
0.10.0a5
0.2.0
0.2.0a1
0.2.0a2
0.2.0a3
0.2.0a4
0.2.0a5
0.2.0a6
0.2.1
0.2.1a0
0.2.2
0.2.3
0.2.3a1
0.2.4
0.2.4a1
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.0a0
0.5.0a1
0.5.0a10
0.5.0a11
0.5.0a12
0.5.0a13
0.5.0a2
0.5.0a3
0.5.0a4
0.5.0a5
0.5.0a6
0.5.0a7
0.5.0a8
0.5.0a9
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.14
0.5.15
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.0a1
0.6.0a2
0.6.0a3
0.6.0a4
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
0.9.0rc0
0.9.1
0.9.2
0.9.3
References Updated Jun 09, 2026 · Source: OSV.dev |
0.10.0a2
pre
Dependencies (55)
+ 47 more |
|
0.10.0a1
pre
1 CVE
CVE-2026-45758
PYSEC-2026-206
GHSA-xmpw-2vmm-p4p6
Jun 05, 2026
9.6
/ 10
Critical
Network
Low
None
Required
Changed
High
High
High
Guardrails AI is a Python framework that helps build AI applications. On May 11, 2026 at approximately 6:00 PM Pacific, an attacker published a malicious version of Affected versions
0.1.0
0.1.0rc1
0.1.0rc2
0.1.0rc3
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
+ 92 more Show less
0.1.9
0.10.0
0.10.0a0
0.10.0a1
0.10.0a2
0.10.0a3
0.10.0a4
0.10.0a5
0.2.0
0.2.0a1
0.2.0a2
0.2.0a3
0.2.0a4
0.2.0a5
0.2.0a6
0.2.1
0.2.1a0
0.2.2
0.2.3
0.2.3a1
0.2.4
0.2.4a1
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.0a0
0.5.0a1
0.5.0a10
0.5.0a11
0.5.0a12
0.5.0a13
0.5.0a2
0.5.0a3
0.5.0a4
0.5.0a5
0.5.0a6
0.5.0a7
0.5.0a8
0.5.0a9
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.14
0.5.15
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.0a1
0.6.0a2
0.6.0a3
0.6.0a4
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
0.9.0rc0
0.9.1
0.9.2
0.9.3
References Updated Jun 09, 2026 · Source: OSV.dev |
0.10.0a1
pre
Dependencies (55)
+ 47 more |
|
0.10.0a0
pre
1 CVE
CVE-2026-45758
PYSEC-2026-206
GHSA-xmpw-2vmm-p4p6
Jun 05, 2026
9.6
/ 10
Critical
Network
Low
None
Required
Changed
High
High
High
Guardrails AI is a Python framework that helps build AI applications. On May 11, 2026 at approximately 6:00 PM Pacific, an attacker published a malicious version of Affected versions
0.1.0
0.1.0rc1
0.1.0rc2
0.1.0rc3
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
+ 92 more Show less
0.1.9
0.10.0
0.10.0a0
0.10.0a1
0.10.0a2
0.10.0a3
0.10.0a4
0.10.0a5
0.2.0
0.2.0a1
0.2.0a2
0.2.0a3
0.2.0a4
0.2.0a5
0.2.0a6
0.2.1
0.2.1a0
0.2.2
0.2.3
0.2.3a1
0.2.4
0.2.4a1
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.0a0
0.5.0a1
0.5.0a10
0.5.0a11
0.5.0a12
0.5.0a13
0.5.0a2
0.5.0a3
0.5.0a4
0.5.0a5
0.5.0a6
0.5.0a7
0.5.0a8
0.5.0a9
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.14
0.5.15
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.0a1
0.6.0a2
0.6.0a3
0.6.0a4
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
0.9.0rc0
0.9.1
0.9.2
0.9.3
References Updated Jun 09, 2026 · Source: OSV.dev |
0.10.0a0
pre
Dependencies (55)
+ 47 more |
|
0.9.2
patch
1 CVE
CVE-2026-45758
PYSEC-2026-206
GHSA-xmpw-2vmm-p4p6
Jun 05, 2026
9.6
/ 10
Critical
Network
Low
None
Required
Changed
High
High
High
Guardrails AI is a Python framework that helps build AI applications. On May 11, 2026 at approximately 6:00 PM Pacific, an attacker published a malicious version of Affected versions
0.1.0
0.1.0rc1
0.1.0rc2
0.1.0rc3
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
+ 92 more Show less
0.1.9
0.10.0
0.10.0a0
0.10.0a1
0.10.0a2
0.10.0a3
0.10.0a4
0.10.0a5
0.2.0
0.2.0a1
0.2.0a2
0.2.0a3
0.2.0a4
0.2.0a5
0.2.0a6
0.2.1
0.2.1a0
0.2.2
0.2.3
0.2.3a1
0.2.4
0.2.4a1
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.0a0
0.5.0a1
0.5.0a10
0.5.0a11
0.5.0a12
0.5.0a13
0.5.0a2
0.5.0a3
0.5.0a4
0.5.0a5
0.5.0a6
0.5.0a7
0.5.0a8
0.5.0a9
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.14
0.5.15
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.0a1
0.6.0a2
0.6.0a3
0.6.0a4
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
0.9.0rc0
0.9.1
0.9.2
0.9.3
References Updated Jun 09, 2026 · Source: OSV.dev |
0.9.2
patch
Dependencies (56)
+ 48 more |
|
0.9.1
patch
1 CVE
CVE-2026-45758
PYSEC-2026-206
GHSA-xmpw-2vmm-p4p6
Jun 05, 2026
9.6
/ 10
Critical
Network
Low
None
Required
Changed
High
High
High
Guardrails AI is a Python framework that helps build AI applications. On May 11, 2026 at approximately 6:00 PM Pacific, an attacker published a malicious version of Affected versions
0.1.0
0.1.0rc1
0.1.0rc2
0.1.0rc3
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
+ 92 more Show less
0.1.9
0.10.0
0.10.0a0
0.10.0a1
0.10.0a2
0.10.0a3
0.10.0a4
0.10.0a5
0.2.0
0.2.0a1
0.2.0a2
0.2.0a3
0.2.0a4
0.2.0a5
0.2.0a6
0.2.1
0.2.1a0
0.2.2
0.2.3
0.2.3a1
0.2.4
0.2.4a1
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.0a0
0.5.0a1
0.5.0a10
0.5.0a11
0.5.0a12
0.5.0a13
0.5.0a2
0.5.0a3
0.5.0a4
0.5.0a5
0.5.0a6
0.5.0a7
0.5.0a8
0.5.0a9
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.14
0.5.15
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.0a1
0.6.0a2
0.6.0a3
0.6.0a4
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
0.9.0rc0
0.9.1
0.9.2
0.9.3
References Updated Jun 09, 2026 · Source: OSV.dev |
0.9.1
patch
Dependencies (66)
+ 58 more |
|
0.8.2
patch
1 CVE
CVE-2026-45758
PYSEC-2026-206
GHSA-xmpw-2vmm-p4p6
Jun 05, 2026
9.6
/ 10
Critical
Network
Low
None
Required
Changed
High
High
High
Guardrails AI is a Python framework that helps build AI applications. On May 11, 2026 at approximately 6:00 PM Pacific, an attacker published a malicious version of Affected versions
0.1.0
0.1.0rc1
0.1.0rc2
0.1.0rc3
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
+ 92 more Show less
0.1.9
0.10.0
0.10.0a0
0.10.0a1
0.10.0a2
0.10.0a3
0.10.0a4
0.10.0a5
0.2.0
0.2.0a1
0.2.0a2
0.2.0a3
0.2.0a4
0.2.0a5
0.2.0a6
0.2.1
0.2.1a0
0.2.2
0.2.3
0.2.3a1
0.2.4
0.2.4a1
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.0a0
0.5.0a1
0.5.0a10
0.5.0a11
0.5.0a12
0.5.0a13
0.5.0a2
0.5.0a3
0.5.0a4
0.5.0a5
0.5.0a6
0.5.0a7
0.5.0a8
0.5.0a9
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.14
0.5.15
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.0a1
0.6.0a2
0.6.0a3
0.6.0a4
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
0.9.0rc0
0.9.1
0.9.2
0.9.3
References Updated Jun 09, 2026 · Source: OSV.dev |
0.8.2
patch
Dependencies (66)
+ 58 more |
|
0.9.0
minor
1 CVE
CVE-2026-45758
PYSEC-2026-206
GHSA-xmpw-2vmm-p4p6
Jun 05, 2026
9.6
/ 10
Critical
Network
Low
None
Required
Changed
High
High
High
Guardrails AI is a Python framework that helps build AI applications. On May 11, 2026 at approximately 6:00 PM Pacific, an attacker published a malicious version of Affected versions
0.1.0
0.1.0rc1
0.1.0rc2
0.1.0rc3
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
+ 92 more Show less
0.1.9
0.10.0
0.10.0a0
0.10.0a1
0.10.0a2
0.10.0a3
0.10.0a4
0.10.0a5
0.2.0
0.2.0a1
0.2.0a2
0.2.0a3
0.2.0a4
0.2.0a5
0.2.0a6
0.2.1
0.2.1a0
0.2.2
0.2.3
0.2.3a1
0.2.4
0.2.4a1
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.0a0
0.5.0a1
0.5.0a10
0.5.0a11
0.5.0a12
0.5.0a13
0.5.0a2
0.5.0a3
0.5.0a4
0.5.0a5
0.5.0a6
0.5.0a7
0.5.0a8
0.5.0a9
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.14
0.5.15
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.0a1
0.6.0a2
0.6.0a3
0.6.0a4
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
0.9.0rc0
0.9.1
0.9.2
0.9.3
References Updated Jun 09, 2026 · Source: OSV.dev |
0.9.0
minor
Dependencies (66)
+ 58 more |
|
0.9.0rc0
pre
1 CVE
CVE-2026-45758
PYSEC-2026-206
GHSA-xmpw-2vmm-p4p6
Jun 05, 2026
9.6
/ 10
Critical
Network
Low
None
Required
Changed
High
High
High
Guardrails AI is a Python framework that helps build AI applications. On May 11, 2026 at approximately 6:00 PM Pacific, an attacker published a malicious version of Affected versions
0.1.0
0.1.0rc1
0.1.0rc2
0.1.0rc3
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
+ 92 more Show less
0.1.9
0.10.0
0.10.0a0
0.10.0a1
0.10.0a2
0.10.0a3
0.10.0a4
0.10.0a5
0.2.0
0.2.0a1
0.2.0a2
0.2.0a3
0.2.0a4
0.2.0a5
0.2.0a6
0.2.1
0.2.1a0
0.2.2
0.2.3
0.2.3a1
0.2.4
0.2.4a1
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.0a0
0.5.0a1
0.5.0a10
0.5.0a11
0.5.0a12
0.5.0a13
0.5.0a2
0.5.0a3
0.5.0a4
0.5.0a5
0.5.0a6
0.5.0a7
0.5.0a8
0.5.0a9
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.14
0.5.15
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.0a1
0.6.0a2
0.6.0a3
0.6.0a4
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
0.9.0rc0
0.9.1
0.9.2
0.9.3
References Updated Jun 09, 2026 · Source: OSV.dev |
0.9.0rc0
pre
Dependencies (66)
+ 58 more |
|
0.8.1
patch
1 CVE
CVE-2026-45758
PYSEC-2026-206
GHSA-xmpw-2vmm-p4p6
Jun 05, 2026
9.6
/ 10
Critical
Network
Low
None
Required
Changed
High
High
High
Guardrails AI is a Python framework that helps build AI applications. On May 11, 2026 at approximately 6:00 PM Pacific, an attacker published a malicious version of Affected versions
0.1.0
0.1.0rc1
0.1.0rc2
0.1.0rc3
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
+ 92 more Show less
0.1.9
0.10.0
0.10.0a0
0.10.0a1
0.10.0a2
0.10.0a3
0.10.0a4
0.10.0a5
0.2.0
0.2.0a1
0.2.0a2
0.2.0a3
0.2.0a4
0.2.0a5
0.2.0a6
0.2.1
0.2.1a0
0.2.2
0.2.3
0.2.3a1
0.2.4
0.2.4a1
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.0a0
0.5.0a1
0.5.0a10
0.5.0a11
0.5.0a12
0.5.0a13
0.5.0a2
0.5.0a3
0.5.0a4
0.5.0a5
0.5.0a6
0.5.0a7
0.5.0a8
0.5.0a9
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.14
0.5.15
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.0a1
0.6.0a2
0.6.0a3
0.6.0a4
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
0.9.0rc0
0.9.1
0.9.2
0.9.3
References Updated Jun 09, 2026 · Source: OSV.dev |
0.8.1
patch
Dependencies (66)
+ 58 more |
|
0.8.0
minor
1 CVE
CVE-2026-45758
PYSEC-2026-206
GHSA-xmpw-2vmm-p4p6
Jun 05, 2026
9.6
/ 10
Critical
Network
Low
None
Required
Changed
High
High
High
Guardrails AI is a Python framework that helps build AI applications. On May 11, 2026 at approximately 6:00 PM Pacific, an attacker published a malicious version of Affected versions
0.1.0
0.1.0rc1
0.1.0rc2
0.1.0rc3
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
+ 92 more Show less
0.1.9
0.10.0
0.10.0a0
0.10.0a1
0.10.0a2
0.10.0a3
0.10.0a4
0.10.0a5
0.2.0
0.2.0a1
0.2.0a2
0.2.0a3
0.2.0a4
0.2.0a5
0.2.0a6
0.2.1
0.2.1a0
0.2.2
0.2.3
0.2.3a1
0.2.4
0.2.4a1
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.0a0
0.5.0a1
0.5.0a10
0.5.0a11
0.5.0a12
0.5.0a13
0.5.0a2
0.5.0a3
0.5.0a4
0.5.0a5
0.5.0a6
0.5.0a7
0.5.0a8
0.5.0a9
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.14
0.5.15
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.0a1
0.6.0a2
0.6.0a3
0.6.0a4
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
0.9.0rc0
0.9.1
0.9.2
0.9.3
References Updated Jun 09, 2026 · Source: OSV.dev |
0.8.0
minor
Dependencies (66)
+ 58 more |
|
0.7.3
patch
1 CVE
CVE-2026-45758
PYSEC-2026-206
GHSA-xmpw-2vmm-p4p6
Jun 05, 2026
9.6
/ 10
Critical
Network
Low
None
Required
Changed
High
High
High
Guardrails AI is a Python framework that helps build AI applications. On May 11, 2026 at approximately 6:00 PM Pacific, an attacker published a malicious version of Affected versions
0.1.0
0.1.0rc1
0.1.0rc2
0.1.0rc3
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
+ 92 more Show less
0.1.9
0.10.0
0.10.0a0
0.10.0a1
0.10.0a2
0.10.0a3
0.10.0a4
0.10.0a5
0.2.0
0.2.0a1
0.2.0a2
0.2.0a3
0.2.0a4
0.2.0a5
0.2.0a6
0.2.1
0.2.1a0
0.2.2
0.2.3
0.2.3a1
0.2.4
0.2.4a1
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.0a0
0.5.0a1
0.5.0a10
0.5.0a11
0.5.0a12
0.5.0a13
0.5.0a2
0.5.0a3
0.5.0a4
0.5.0a5
0.5.0a6
0.5.0a7
0.5.0a8
0.5.0a9
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.14
0.5.15
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.0a1
0.6.0a2
0.6.0a3
0.6.0a4
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
0.9.0rc0
0.9.1
0.9.2
0.9.3
References Updated Jun 09, 2026 · Source: OSV.dev |
0.7.3
patch
Dependencies (66)
+ 58 more |
|
0.7.2
patch
1 CVE
CVE-2026-45758
PYSEC-2026-206
GHSA-xmpw-2vmm-p4p6
Jun 05, 2026
9.6
/ 10
Critical
Network
Low
None
Required
Changed
High
High
High
Guardrails AI is a Python framework that helps build AI applications. On May 11, 2026 at approximately 6:00 PM Pacific, an attacker published a malicious version of Affected versions
0.1.0
0.1.0rc1
0.1.0rc2
0.1.0rc3
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
+ 92 more Show less
0.1.9
0.10.0
0.10.0a0
0.10.0a1
0.10.0a2
0.10.0a3
0.10.0a4
0.10.0a5
0.2.0
0.2.0a1
0.2.0a2
0.2.0a3
0.2.0a4
0.2.0a5
0.2.0a6
0.2.1
0.2.1a0
0.2.2
0.2.3
0.2.3a1
0.2.4
0.2.4a1
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.0a0
0.5.0a1
0.5.0a10
0.5.0a11
0.5.0a12
0.5.0a13
0.5.0a2
0.5.0a3
0.5.0a4
0.5.0a5
0.5.0a6
0.5.0a7
0.5.0a8
0.5.0a9
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.14
0.5.15
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.0a1
0.6.0a2
0.6.0a3
0.6.0a4
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
0.9.0rc0
0.9.1
0.9.2
0.9.3
References Updated Jun 09, 2026 · Source: OSV.dev |
0.7.2
patch
Dependencies (66)
+ 58 more |
|
0.7.1
patch
1 CVE
CVE-2026-45758
PYSEC-2026-206
GHSA-xmpw-2vmm-p4p6
Jun 05, 2026
9.6
/ 10
Critical
Network
Low
None
Required
Changed
High
High
High
Guardrails AI is a Python framework that helps build AI applications. On May 11, 2026 at approximately 6:00 PM Pacific, an attacker published a malicious version of Affected versions
0.1.0
0.1.0rc1
0.1.0rc2
0.1.0rc3
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
+ 92 more Show less
0.1.9
0.10.0
0.10.0a0
0.10.0a1
0.10.0a2
0.10.0a3
0.10.0a4
0.10.0a5
0.2.0
0.2.0a1
0.2.0a2
0.2.0a3
0.2.0a4
0.2.0a5
0.2.0a6
0.2.1
0.2.1a0
0.2.2
0.2.3
0.2.3a1
0.2.4
0.2.4a1
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.0a0
0.5.0a1
0.5.0a10
0.5.0a11
0.5.0a12
0.5.0a13
0.5.0a2
0.5.0a3
0.5.0a4
0.5.0a5
0.5.0a6
0.5.0a7
0.5.0a8
0.5.0a9
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.14
0.5.15
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.0a1
0.6.0a2
0.6.0a3
0.6.0a4
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
0.9.0rc0
0.9.1
0.9.2
0.9.3
References Updated Jun 09, 2026 · Source: OSV.dev |
0.7.1
patch
Dependencies (66)
+ 58 more |
|
0.7.0
minor
1 CVE
CVE-2026-45758
PYSEC-2026-206
GHSA-xmpw-2vmm-p4p6
Jun 05, 2026
9.6
/ 10
Critical
Network
Low
None
Required
Changed
High
High
High
Guardrails AI is a Python framework that helps build AI applications. On May 11, 2026 at approximately 6:00 PM Pacific, an attacker published a malicious version of Affected versions
0.1.0
0.1.0rc1
0.1.0rc2
0.1.0rc3
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
+ 92 more Show less
0.1.9
0.10.0
0.10.0a0
0.10.0a1
0.10.0a2
0.10.0a3
0.10.0a4
0.10.0a5
0.2.0
0.2.0a1
0.2.0a2
0.2.0a3
0.2.0a4
0.2.0a5
0.2.0a6
0.2.1
0.2.1a0
0.2.2
0.2.3
0.2.3a1
0.2.4
0.2.4a1
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.0a0
0.5.0a1
0.5.0a10
0.5.0a11
0.5.0a12
0.5.0a13
0.5.0a2
0.5.0a3
0.5.0a4
0.5.0a5
0.5.0a6
0.5.0a7
0.5.0a8
0.5.0a9
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.14
0.5.15
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.0a1
0.6.0a2
0.6.0a3
0.6.0a4
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
0.9.0rc0
0.9.1
0.9.2
0.9.3
References Updated Jun 09, 2026 · Source: OSV.dev |
0.7.0
minor
Dependencies (66)
+ 58 more |
|
0.6.8
patch
1 CVE
CVE-2026-45758
PYSEC-2026-206
GHSA-xmpw-2vmm-p4p6
Jun 05, 2026
9.6
/ 10
Critical
Network
Low
None
Required
Changed
High
High
High
Guardrails AI is a Python framework that helps build AI applications. On May 11, 2026 at approximately 6:00 PM Pacific, an attacker published a malicious version of Affected versions
0.1.0
0.1.0rc1
0.1.0rc2
0.1.0rc3
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
+ 92 more Show less
0.1.9
0.10.0
0.10.0a0
0.10.0a1
0.10.0a2
0.10.0a3
0.10.0a4
0.10.0a5
0.2.0
0.2.0a1
0.2.0a2
0.2.0a3
0.2.0a4
0.2.0a5
0.2.0a6
0.2.1
0.2.1a0
0.2.2
0.2.3
0.2.3a1
0.2.4
0.2.4a1
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.0a0
0.5.0a1
0.5.0a10
0.5.0a11
0.5.0a12
0.5.0a13
0.5.0a2
0.5.0a3
0.5.0a4
0.5.0a5
0.5.0a6
0.5.0a7
0.5.0a8
0.5.0a9
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.14
0.5.15
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.0a1
0.6.0a2
0.6.0a3
0.6.0a4
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
0.9.0rc0
0.9.1
0.9.2
0.9.3
References Updated Jun 09, 2026 · Source: OSV.dev |
0.6.8
patch
Dependencies (66)
+ 58 more |
|
0.6.7
patch
2 CVEs
CVE-2026-31233
PYSEC-2026-347
GHSA-r6hf-g5x6-7pv9
Jun 29, 2026
Guardrails AI contains a code injection vulnerability in its Hub package installation mechanism
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Guardrails AI thru 0.6.7 contains a code injection vulnerability (CWE-94) in its Hub package installation mechanism. When installing validator packages via guardrails hub install, the system retrieves a manifest from the Guardrails Hub and dynamically executes a script specified in the post_install field. The script path is constructed from untrusted manifest data and executed without proper validation or sanitization, allowing remote code execution. An attacker who can publish malicious packages to the Hub can inject arbitrary code that will be executed on any system where a victim installs the malicious package. Affected versions
0.1.0
0.1.0rc1
0.1.0rc2
0.1.0rc3
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
+ 72 more Show less
0.1.9
0.2.0
0.2.0a1
0.2.0a2
0.2.0a3
0.2.0a4
0.2.0a5
0.2.0a6
0.2.1
0.2.1a0
0.2.2
0.2.3
0.2.3a1
0.2.4
0.2.4a1
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.0a0
0.5.0a1
0.5.0a10
0.5.0a11
0.5.0a12
0.5.0a13
0.5.0a2
0.5.0a3
0.5.0a4
0.5.0a5
0.5.0a6
0.5.0a7
0.5.0a8
0.5.0a9
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.14
0.5.15
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.0a1
0.6.0a2
0.6.0a3
0.6.0a4
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-45758
PYSEC-2026-206
GHSA-xmpw-2vmm-p4p6
Jun 05, 2026
9.6
/ 10
Critical
Network
Low
None
Required
Changed
High
High
High
Guardrails AI is a Python framework that helps build AI applications. On May 11, 2026 at approximately 6:00 PM Pacific, an attacker published a malicious version of Affected versions
0.1.0
0.1.0rc1
0.1.0rc2
0.1.0rc3
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
+ 92 more Show less
0.1.9
0.10.0
0.10.0a0
0.10.0a1
0.10.0a2
0.10.0a3
0.10.0a4
0.10.0a5
0.2.0
0.2.0a1
0.2.0a2
0.2.0a3
0.2.0a4
0.2.0a5
0.2.0a6
0.2.1
0.2.1a0
0.2.2
0.2.3
0.2.3a1
0.2.4
0.2.4a1
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.0a0
0.5.0a1
0.5.0a10
0.5.0a11
0.5.0a12
0.5.0a13
0.5.0a2
0.5.0a3
0.5.0a4
0.5.0a5
0.5.0a6
0.5.0a7
0.5.0a8
0.5.0a9
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.14
0.5.15
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.0a1
0.6.0a2
0.6.0a3
0.6.0a4
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
0.9.0rc0
0.9.1
0.9.2
0.9.3
References Updated Jun 09, 2026 · Source: OSV.dev |
0.6.7
patch
Dependencies (66)
+ 58 more |
|
0.6.6
patch
2 CVEs
CVE-2026-31233
PYSEC-2026-347
GHSA-r6hf-g5x6-7pv9
Jun 29, 2026
Guardrails AI contains a code injection vulnerability in its Hub package installation mechanism
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Guardrails AI thru 0.6.7 contains a code injection vulnerability (CWE-94) in its Hub package installation mechanism. When installing validator packages via guardrails hub install, the system retrieves a manifest from the Guardrails Hub and dynamically executes a script specified in the post_install field. The script path is constructed from untrusted manifest data and executed without proper validation or sanitization, allowing remote code execution. An attacker who can publish malicious packages to the Hub can inject arbitrary code that will be executed on any system where a victim installs the malicious package. Affected versions
0.1.0
0.1.0rc1
0.1.0rc2
0.1.0rc3
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
+ 72 more Show less
0.1.9
0.2.0
0.2.0a1
0.2.0a2
0.2.0a3
0.2.0a4
0.2.0a5
0.2.0a6
0.2.1
0.2.1a0
0.2.2
0.2.3
0.2.3a1
0.2.4
0.2.4a1
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.0a0
0.5.0a1
0.5.0a10
0.5.0a11
0.5.0a12
0.5.0a13
0.5.0a2
0.5.0a3
0.5.0a4
0.5.0a5
0.5.0a6
0.5.0a7
0.5.0a8
0.5.0a9
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.14
0.5.15
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.0a1
0.6.0a2
0.6.0a3
0.6.0a4
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-45758
PYSEC-2026-206
GHSA-xmpw-2vmm-p4p6
Jun 05, 2026
9.6
/ 10
Critical
Network
Low
None
Required
Changed
High
High
High
Guardrails AI is a Python framework that helps build AI applications. On May 11, 2026 at approximately 6:00 PM Pacific, an attacker published a malicious version of Affected versions
0.1.0
0.1.0rc1
0.1.0rc2
0.1.0rc3
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
+ 92 more Show less
0.1.9
0.10.0
0.10.0a0
0.10.0a1
0.10.0a2
0.10.0a3
0.10.0a4
0.10.0a5
0.2.0
0.2.0a1
0.2.0a2
0.2.0a3
0.2.0a4
0.2.0a5
0.2.0a6
0.2.1
0.2.1a0
0.2.2
0.2.3
0.2.3a1
0.2.4
0.2.4a1
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.0a0
0.5.0a1
0.5.0a10
0.5.0a11
0.5.0a12
0.5.0a13
0.5.0a2
0.5.0a3
0.5.0a4
0.5.0a5
0.5.0a6
0.5.0a7
0.5.0a8
0.5.0a9
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.14
0.5.15
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.0a1
0.6.0a2
0.6.0a3
0.6.0a4
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
0.9.0rc0
0.9.1
0.9.2
0.9.3
References Updated Jun 09, 2026 · Source: OSV.dev |
0.6.6
patch
Dependencies (44)
+ 36 more |
|
0.6.5
patch
2 CVEs
CVE-2026-31233
PYSEC-2026-347
GHSA-r6hf-g5x6-7pv9
Jun 29, 2026
Guardrails AI contains a code injection vulnerability in its Hub package installation mechanism
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Guardrails AI thru 0.6.7 contains a code injection vulnerability (CWE-94) in its Hub package installation mechanism. When installing validator packages via guardrails hub install, the system retrieves a manifest from the Guardrails Hub and dynamically executes a script specified in the post_install field. The script path is constructed from untrusted manifest data and executed without proper validation or sanitization, allowing remote code execution. An attacker who can publish malicious packages to the Hub can inject arbitrary code that will be executed on any system where a victim installs the malicious package. Affected versions
0.1.0
0.1.0rc1
0.1.0rc2
0.1.0rc3
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
+ 72 more Show less
0.1.9
0.2.0
0.2.0a1
0.2.0a2
0.2.0a3
0.2.0a4
0.2.0a5
0.2.0a6
0.2.1
0.2.1a0
0.2.2
0.2.3
0.2.3a1
0.2.4
0.2.4a1
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.0a0
0.5.0a1
0.5.0a10
0.5.0a11
0.5.0a12
0.5.0a13
0.5.0a2
0.5.0a3
0.5.0a4
0.5.0a5
0.5.0a6
0.5.0a7
0.5.0a8
0.5.0a9
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.14
0.5.15
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.0a1
0.6.0a2
0.6.0a3
0.6.0a4
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-45758
PYSEC-2026-206
GHSA-xmpw-2vmm-p4p6
Jun 05, 2026
9.6
/ 10
Critical
Network
Low
None
Required
Changed
High
High
High
Guardrails AI is a Python framework that helps build AI applications. On May 11, 2026 at approximately 6:00 PM Pacific, an attacker published a malicious version of Affected versions
0.1.0
0.1.0rc1
0.1.0rc2
0.1.0rc3
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
+ 92 more Show less
0.1.9
0.10.0
0.10.0a0
0.10.0a1
0.10.0a2
0.10.0a3
0.10.0a4
0.10.0a5
0.2.0
0.2.0a1
0.2.0a2
0.2.0a3
0.2.0a4
0.2.0a5
0.2.0a6
0.2.1
0.2.1a0
0.2.2
0.2.3
0.2.3a1
0.2.4
0.2.4a1
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.0a0
0.5.0a1
0.5.0a10
0.5.0a11
0.5.0a12
0.5.0a13
0.5.0a2
0.5.0a3
0.5.0a4
0.5.0a5
0.5.0a6
0.5.0a7
0.5.0a8
0.5.0a9
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.14
0.5.15
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.0a1
0.6.0a2
0.6.0a3
0.6.0a4
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
0.9.0rc0
0.9.1
0.9.2
0.9.3
References Updated Jun 09, 2026 · Source: OSV.dev |
0.6.5
patch
Dependencies (44)
+ 36 more |
|
0.6.4
patch
2 CVEs
CVE-2026-31233
PYSEC-2026-347
GHSA-r6hf-g5x6-7pv9
Jun 29, 2026
Guardrails AI contains a code injection vulnerability in its Hub package installation mechanism
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Guardrails AI thru 0.6.7 contains a code injection vulnerability (CWE-94) in its Hub package installation mechanism. When installing validator packages via guardrails hub install, the system retrieves a manifest from the Guardrails Hub and dynamically executes a script specified in the post_install field. The script path is constructed from untrusted manifest data and executed without proper validation or sanitization, allowing remote code execution. An attacker who can publish malicious packages to the Hub can inject arbitrary code that will be executed on any system where a victim installs the malicious package. Affected versions
0.1.0
0.1.0rc1
0.1.0rc2
0.1.0rc3
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
+ 72 more Show less
0.1.9
0.2.0
0.2.0a1
0.2.0a2
0.2.0a3
0.2.0a4
0.2.0a5
0.2.0a6
0.2.1
0.2.1a0
0.2.2
0.2.3
0.2.3a1
0.2.4
0.2.4a1
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.0a0
0.5.0a1
0.5.0a10
0.5.0a11
0.5.0a12
0.5.0a13
0.5.0a2
0.5.0a3
0.5.0a4
0.5.0a5
0.5.0a6
0.5.0a7
0.5.0a8
0.5.0a9
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.14
0.5.15
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.0a1
0.6.0a2
0.6.0a3
0.6.0a4
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-45758
PYSEC-2026-206
GHSA-xmpw-2vmm-p4p6
Jun 05, 2026
9.6
/ 10
Critical
Network
Low
None
Required
Changed
High
High
High
Guardrails AI is a Python framework that helps build AI applications. On May 11, 2026 at approximately 6:00 PM Pacific, an attacker published a malicious version of Affected versions
0.1.0
0.1.0rc1
0.1.0rc2
0.1.0rc3
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
+ 92 more Show less
0.1.9
0.10.0
0.10.0a0
0.10.0a1
0.10.0a2
0.10.0a3
0.10.0a4
0.10.0a5
0.2.0
0.2.0a1
0.2.0a2
0.2.0a3
0.2.0a4
0.2.0a5
0.2.0a6
0.2.1
0.2.1a0
0.2.2
0.2.3
0.2.3a1
0.2.4
0.2.4a1
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.0a0
0.5.0a1
0.5.0a10
0.5.0a11
0.5.0a12
0.5.0a13
0.5.0a2
0.5.0a3
0.5.0a4
0.5.0a5
0.5.0a6
0.5.0a7
0.5.0a8
0.5.0a9
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.14
0.5.15
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.0a1
0.6.0a2
0.6.0a3
0.6.0a4
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
0.9.0rc0
0.9.1
0.9.2
0.9.3
References Updated Jun 09, 2026 · Source: OSV.dev |
0.6.4
patch
Dependencies (44)
+ 36 more |
|
0.6.3
patch
2 CVEs
CVE-2026-31233
PYSEC-2026-347
GHSA-r6hf-g5x6-7pv9
Jun 29, 2026
Guardrails AI contains a code injection vulnerability in its Hub package installation mechanism
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Guardrails AI thru 0.6.7 contains a code injection vulnerability (CWE-94) in its Hub package installation mechanism. When installing validator packages via guardrails hub install, the system retrieves a manifest from the Guardrails Hub and dynamically executes a script specified in the post_install field. The script path is constructed from untrusted manifest data and executed without proper validation or sanitization, allowing remote code execution. An attacker who can publish malicious packages to the Hub can inject arbitrary code that will be executed on any system where a victim installs the malicious package. Affected versions
0.1.0
0.1.0rc1
0.1.0rc2
0.1.0rc3
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
+ 72 more Show less
0.1.9
0.2.0
0.2.0a1
0.2.0a2
0.2.0a3
0.2.0a4
0.2.0a5
0.2.0a6
0.2.1
0.2.1a0
0.2.2
0.2.3
0.2.3a1
0.2.4
0.2.4a1
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.0a0
0.5.0a1
0.5.0a10
0.5.0a11
0.5.0a12
0.5.0a13
0.5.0a2
0.5.0a3
0.5.0a4
0.5.0a5
0.5.0a6
0.5.0a7
0.5.0a8
0.5.0a9
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.14
0.5.15
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.0a1
0.6.0a2
0.6.0a3
0.6.0a4
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-45758
PYSEC-2026-206
GHSA-xmpw-2vmm-p4p6
Jun 05, 2026
9.6
/ 10
Critical
Network
Low
None
Required
Changed
High
High
High
Guardrails AI is a Python framework that helps build AI applications. On May 11, 2026 at approximately 6:00 PM Pacific, an attacker published a malicious version of Affected versions
0.1.0
0.1.0rc1
0.1.0rc2
0.1.0rc3
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
+ 92 more Show less
0.1.9
0.10.0
0.10.0a0
0.10.0a1
0.10.0a2
0.10.0a3
0.10.0a4
0.10.0a5
0.2.0
0.2.0a1
0.2.0a2
0.2.0a3
0.2.0a4
0.2.0a5
0.2.0a6
0.2.1
0.2.1a0
0.2.2
0.2.3
0.2.3a1
0.2.4
0.2.4a1
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.0a0
0.5.0a1
0.5.0a10
0.5.0a11
0.5.0a12
0.5.0a13
0.5.0a2
0.5.0a3
0.5.0a4
0.5.0a5
0.5.0a6
0.5.0a7
0.5.0a8
0.5.0a9
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.14
0.5.15
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.0a1
0.6.0a2
0.6.0a3
0.6.0a4
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
0.9.0rc0
0.9.1
0.9.2
0.9.3
References Updated Jun 09, 2026 · Source: OSV.dev |
0.6.3
patch
Dependencies (46)
+ 38 more |
|
0.6.2
patch
2 CVEs
CVE-2026-31233
PYSEC-2026-347
GHSA-r6hf-g5x6-7pv9
Jun 29, 2026
Guardrails AI contains a code injection vulnerability in its Hub package installation mechanism
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Guardrails AI thru 0.6.7 contains a code injection vulnerability (CWE-94) in its Hub package installation mechanism. When installing validator packages via guardrails hub install, the system retrieves a manifest from the Guardrails Hub and dynamically executes a script specified in the post_install field. The script path is constructed from untrusted manifest data and executed without proper validation or sanitization, allowing remote code execution. An attacker who can publish malicious packages to the Hub can inject arbitrary code that will be executed on any system where a victim installs the malicious package. Affected versions
0.1.0
0.1.0rc1
0.1.0rc2
0.1.0rc3
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
+ 72 more Show less
0.1.9
0.2.0
0.2.0a1
0.2.0a2
0.2.0a3
0.2.0a4
0.2.0a5
0.2.0a6
0.2.1
0.2.1a0
0.2.2
0.2.3
0.2.3a1
0.2.4
0.2.4a1
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.0a0
0.5.0a1
0.5.0a10
0.5.0a11
0.5.0a12
0.5.0a13
0.5.0a2
0.5.0a3
0.5.0a4
0.5.0a5
0.5.0a6
0.5.0a7
0.5.0a8
0.5.0a9
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.14
0.5.15
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.0a1
0.6.0a2
0.6.0a3
0.6.0a4
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-45758
PYSEC-2026-206
GHSA-xmpw-2vmm-p4p6
Jun 05, 2026
9.6
/ 10
Critical
Network
Low
None
Required
Changed
High
High
High
Guardrails AI is a Python framework that helps build AI applications. On May 11, 2026 at approximately 6:00 PM Pacific, an attacker published a malicious version of Affected versions
0.1.0
0.1.0rc1
0.1.0rc2
0.1.0rc3
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
+ 92 more Show less
0.1.9
0.10.0
0.10.0a0
0.10.0a1
0.10.0a2
0.10.0a3
0.10.0a4
0.10.0a5
0.2.0
0.2.0a1
0.2.0a2
0.2.0a3
0.2.0a4
0.2.0a5
0.2.0a6
0.2.1
0.2.1a0
0.2.2
0.2.3
0.2.3a1
0.2.4
0.2.4a1
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.0a0
0.5.0a1
0.5.0a10
0.5.0a11
0.5.0a12
0.5.0a13
0.5.0a2
0.5.0a3
0.5.0a4
0.5.0a5
0.5.0a6
0.5.0a7
0.5.0a8
0.5.0a9
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.14
0.5.15
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.0a1
0.6.0a2
0.6.0a3
0.6.0a4
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
0.9.0rc0
0.9.1
0.9.2
0.9.3
References Updated Jun 09, 2026 · Source: OSV.dev |
0.6.2
patch
Dependencies (46)
+ 38 more |
|
0.6.1
patch
2 CVEs
CVE-2026-31233
PYSEC-2026-347
GHSA-r6hf-g5x6-7pv9
Jun 29, 2026
Guardrails AI contains a code injection vulnerability in its Hub package installation mechanism
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Guardrails AI thru 0.6.7 contains a code injection vulnerability (CWE-94) in its Hub package installation mechanism. When installing validator packages via guardrails hub install, the system retrieves a manifest from the Guardrails Hub and dynamically executes a script specified in the post_install field. The script path is constructed from untrusted manifest data and executed without proper validation or sanitization, allowing remote code execution. An attacker who can publish malicious packages to the Hub can inject arbitrary code that will be executed on any system where a victim installs the malicious package. Affected versions
0.1.0
0.1.0rc1
0.1.0rc2
0.1.0rc3
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
+ 72 more Show less
0.1.9
0.2.0
0.2.0a1
0.2.0a2
0.2.0a3
0.2.0a4
0.2.0a5
0.2.0a6
0.2.1
0.2.1a0
0.2.2
0.2.3
0.2.3a1
0.2.4
0.2.4a1
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.0a0
0.5.0a1
0.5.0a10
0.5.0a11
0.5.0a12
0.5.0a13
0.5.0a2
0.5.0a3
0.5.0a4
0.5.0a5
0.5.0a6
0.5.0a7
0.5.0a8
0.5.0a9
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.14
0.5.15
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.0a1
0.6.0a2
0.6.0a3
0.6.0a4
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-45758
PYSEC-2026-206
GHSA-xmpw-2vmm-p4p6
Jun 05, 2026
9.6
/ 10
Critical
Network
Low
None
Required
Changed
High
High
High
Guardrails AI is a Python framework that helps build AI applications. On May 11, 2026 at approximately 6:00 PM Pacific, an attacker published a malicious version of Affected versions
0.1.0
0.1.0rc1
0.1.0rc2
0.1.0rc3
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
+ 92 more Show less
0.1.9
0.10.0
0.10.0a0
0.10.0a1
0.10.0a2
0.10.0a3
0.10.0a4
0.10.0a5
0.2.0
0.2.0a1
0.2.0a2
0.2.0a3
0.2.0a4
0.2.0a5
0.2.0a6
0.2.1
0.2.1a0
0.2.2
0.2.3
0.2.3a1
0.2.4
0.2.4a1
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.0a0
0.5.0a1
0.5.0a10
0.5.0a11
0.5.0a12
0.5.0a13
0.5.0a2
0.5.0a3
0.5.0a4
0.5.0a5
0.5.0a6
0.5.0a7
0.5.0a8
0.5.0a9
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.14
0.5.15
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.0a1
0.6.0a2
0.6.0a3
0.6.0a4
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
0.9.0rc0
0.9.1
0.9.2
0.9.3
References Updated Jun 09, 2026 · Source: OSV.dev |
0.6.1
patch
Dependencies (46)
+ 38 more |
|
0.6.0
minor
2 CVEs
CVE-2026-31233
PYSEC-2026-347
GHSA-r6hf-g5x6-7pv9
Jun 29, 2026
Guardrails AI contains a code injection vulnerability in its Hub package installation mechanism
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Guardrails AI thru 0.6.7 contains a code injection vulnerability (CWE-94) in its Hub package installation mechanism. When installing validator packages via guardrails hub install, the system retrieves a manifest from the Guardrails Hub and dynamically executes a script specified in the post_install field. The script path is constructed from untrusted manifest data and executed without proper validation or sanitization, allowing remote code execution. An attacker who can publish malicious packages to the Hub can inject arbitrary code that will be executed on any system where a victim installs the malicious package. Affected versions
0.1.0
0.1.0rc1
0.1.0rc2
0.1.0rc3
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
+ 72 more Show less
0.1.9
0.2.0
0.2.0a1
0.2.0a2
0.2.0a3
0.2.0a4
0.2.0a5
0.2.0a6
0.2.1
0.2.1a0
0.2.2
0.2.3
0.2.3a1
0.2.4
0.2.4a1
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.0a0
0.5.0a1
0.5.0a10
0.5.0a11
0.5.0a12
0.5.0a13
0.5.0a2
0.5.0a3
0.5.0a4
0.5.0a5
0.5.0a6
0.5.0a7
0.5.0a8
0.5.0a9
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.14
0.5.15
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.0a1
0.6.0a2
0.6.0a3
0.6.0a4
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-45758
PYSEC-2026-206
GHSA-xmpw-2vmm-p4p6
Jun 05, 2026
9.6
/ 10
Critical
Network
Low
None
Required
Changed
High
High
High
Guardrails AI is a Python framework that helps build AI applications. On May 11, 2026 at approximately 6:00 PM Pacific, an attacker published a malicious version of Affected versions
0.1.0
0.1.0rc1
0.1.0rc2
0.1.0rc3
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
+ 92 more Show less
0.1.9
0.10.0
0.10.0a0
0.10.0a1
0.10.0a2
0.10.0a3
0.10.0a4
0.10.0a5
0.2.0
0.2.0a1
0.2.0a2
0.2.0a3
0.2.0a4
0.2.0a5
0.2.0a6
0.2.1
0.2.1a0
0.2.2
0.2.3
0.2.3a1
0.2.4
0.2.4a1
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.0a0
0.5.0a1
0.5.0a10
0.5.0a11
0.5.0a12
0.5.0a13
0.5.0a2
0.5.0a3
0.5.0a4
0.5.0a5
0.5.0a6
0.5.0a7
0.5.0a8
0.5.0a9
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.14
0.5.15
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.0a1
0.6.0a2
0.6.0a3
0.6.0a4
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
0.9.0rc0
0.9.1
0.9.2
0.9.3
References Updated Jun 09, 2026 · Source: OSV.dev |
0.6.0
minor
Dependencies (44)
+ 36 more |
|
0.6.0a4
pre
2 CVEs
CVE-2026-31233
PYSEC-2026-347
GHSA-r6hf-g5x6-7pv9
Jun 29, 2026
Guardrails AI contains a code injection vulnerability in its Hub package installation mechanism
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Guardrails AI thru 0.6.7 contains a code injection vulnerability (CWE-94) in its Hub package installation mechanism. When installing validator packages via guardrails hub install, the system retrieves a manifest from the Guardrails Hub and dynamically executes a script specified in the post_install field. The script path is constructed from untrusted manifest data and executed without proper validation or sanitization, allowing remote code execution. An attacker who can publish malicious packages to the Hub can inject arbitrary code that will be executed on any system where a victim installs the malicious package. Affected versions
0.1.0
0.1.0rc1
0.1.0rc2
0.1.0rc3
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
+ 72 more Show less
0.1.9
0.2.0
0.2.0a1
0.2.0a2
0.2.0a3
0.2.0a4
0.2.0a5
0.2.0a6
0.2.1
0.2.1a0
0.2.2
0.2.3
0.2.3a1
0.2.4
0.2.4a1
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.0a0
0.5.0a1
0.5.0a10
0.5.0a11
0.5.0a12
0.5.0a13
0.5.0a2
0.5.0a3
0.5.0a4
0.5.0a5
0.5.0a6
0.5.0a7
0.5.0a8
0.5.0a9
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.14
0.5.15
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.0a1
0.6.0a2
0.6.0a3
0.6.0a4
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-45758
PYSEC-2026-206
GHSA-xmpw-2vmm-p4p6
Jun 05, 2026
9.6
/ 10
Critical
Network
Low
None
Required
Changed
High
High
High
Guardrails AI is a Python framework that helps build AI applications. On May 11, 2026 at approximately 6:00 PM Pacific, an attacker published a malicious version of Affected versions
0.1.0
0.1.0rc1
0.1.0rc2
0.1.0rc3
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
+ 92 more Show less
0.1.9
0.10.0
0.10.0a0
0.10.0a1
0.10.0a2
0.10.0a3
0.10.0a4
0.10.0a5
0.2.0
0.2.0a1
0.2.0a2
0.2.0a3
0.2.0a4
0.2.0a5
0.2.0a6
0.2.1
0.2.1a0
0.2.2
0.2.3
0.2.3a1
0.2.4
0.2.4a1
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.0a0
0.5.0a1
0.5.0a10
0.5.0a11
0.5.0a12
0.5.0a13
0.5.0a2
0.5.0a3
0.5.0a4
0.5.0a5
0.5.0a6
0.5.0a7
0.5.0a8
0.5.0a9
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.14
0.5.15
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.0a1
0.6.0a2
0.6.0a3
0.6.0a4
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
0.9.0rc0
0.9.1
0.9.2
0.9.3
References Updated Jun 09, 2026 · Source: OSV.dev |
0.6.0a4
pre
Dependencies (44)
+ 36 more |
|
0.6.0a3
pre
2 CVEs
CVE-2026-31233
PYSEC-2026-347
GHSA-r6hf-g5x6-7pv9
Jun 29, 2026
Guardrails AI contains a code injection vulnerability in its Hub package installation mechanism
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Guardrails AI thru 0.6.7 contains a code injection vulnerability (CWE-94) in its Hub package installation mechanism. When installing validator packages via guardrails hub install, the system retrieves a manifest from the Guardrails Hub and dynamically executes a script specified in the post_install field. The script path is constructed from untrusted manifest data and executed without proper validation or sanitization, allowing remote code execution. An attacker who can publish malicious packages to the Hub can inject arbitrary code that will be executed on any system where a victim installs the malicious package. Affected versions
0.1.0
0.1.0rc1
0.1.0rc2
0.1.0rc3
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
+ 72 more Show less
0.1.9
0.2.0
0.2.0a1
0.2.0a2
0.2.0a3
0.2.0a4
0.2.0a5
0.2.0a6
0.2.1
0.2.1a0
0.2.2
0.2.3
0.2.3a1
0.2.4
0.2.4a1
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.0a0
0.5.0a1
0.5.0a10
0.5.0a11
0.5.0a12
0.5.0a13
0.5.0a2
0.5.0a3
0.5.0a4
0.5.0a5
0.5.0a6
0.5.0a7
0.5.0a8
0.5.0a9
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.14
0.5.15
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.0a1
0.6.0a2
0.6.0a3
0.6.0a4
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-45758
PYSEC-2026-206
GHSA-xmpw-2vmm-p4p6
Jun 05, 2026
9.6
/ 10
Critical
Network
Low
None
Required
Changed
High
High
High
Guardrails AI is a Python framework that helps build AI applications. On May 11, 2026 at approximately 6:00 PM Pacific, an attacker published a malicious version of Affected versions
0.1.0
0.1.0rc1
0.1.0rc2
0.1.0rc3
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
+ 92 more Show less
0.1.9
0.10.0
0.10.0a0
0.10.0a1
0.10.0a2
0.10.0a3
0.10.0a4
0.10.0a5
0.2.0
0.2.0a1
0.2.0a2
0.2.0a3
0.2.0a4
0.2.0a5
0.2.0a6
0.2.1
0.2.1a0
0.2.2
0.2.3
0.2.3a1
0.2.4
0.2.4a1
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.0a0
0.5.0a1
0.5.0a10
0.5.0a11
0.5.0a12
0.5.0a13
0.5.0a2
0.5.0a3
0.5.0a4
0.5.0a5
0.5.0a6
0.5.0a7
0.5.0a8
0.5.0a9
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.14
0.5.15
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.0a1
0.6.0a2
0.6.0a3
0.6.0a4
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
0.9.0rc0
0.9.1
0.9.2
0.9.3
References Updated Jun 09, 2026 · Source: OSV.dev |
0.6.0a3
pre
Dependencies (44)
+ 36 more |
|
0.6.0a2
pre
2 CVEs
CVE-2026-31233
PYSEC-2026-347
GHSA-r6hf-g5x6-7pv9
Jun 29, 2026
Guardrails AI contains a code injection vulnerability in its Hub package installation mechanism
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Guardrails AI thru 0.6.7 contains a code injection vulnerability (CWE-94) in its Hub package installation mechanism. When installing validator packages via guardrails hub install, the system retrieves a manifest from the Guardrails Hub and dynamically executes a script specified in the post_install field. The script path is constructed from untrusted manifest data and executed without proper validation or sanitization, allowing remote code execution. An attacker who can publish malicious packages to the Hub can inject arbitrary code that will be executed on any system where a victim installs the malicious package. Affected versions
0.1.0
0.1.0rc1
0.1.0rc2
0.1.0rc3
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
+ 72 more Show less
0.1.9
0.2.0
0.2.0a1
0.2.0a2
0.2.0a3
0.2.0a4
0.2.0a5
0.2.0a6
0.2.1
0.2.1a0
0.2.2
0.2.3
0.2.3a1
0.2.4
0.2.4a1
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.0a0
0.5.0a1
0.5.0a10
0.5.0a11
0.5.0a12
0.5.0a13
0.5.0a2
0.5.0a3
0.5.0a4
0.5.0a5
0.5.0a6
0.5.0a7
0.5.0a8
0.5.0a9
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.14
0.5.15
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.0a1
0.6.0a2
0.6.0a3
0.6.0a4
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-45758
PYSEC-2026-206
GHSA-xmpw-2vmm-p4p6
Jun 05, 2026
9.6
/ 10
Critical
Network
Low
None
Required
Changed
High
High
High
Guardrails AI is a Python framework that helps build AI applications. On May 11, 2026 at approximately 6:00 PM Pacific, an attacker published a malicious version of Affected versions
0.1.0
0.1.0rc1
0.1.0rc2
0.1.0rc3
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
+ 92 more Show less
0.1.9
0.10.0
0.10.0a0
0.10.0a1
0.10.0a2
0.10.0a3
0.10.0a4
0.10.0a5
0.2.0
0.2.0a1
0.2.0a2
0.2.0a3
0.2.0a4
0.2.0a5
0.2.0a6
0.2.1
0.2.1a0
0.2.2
0.2.3
0.2.3a1
0.2.4
0.2.4a1
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.0a0
0.5.0a1
0.5.0a10
0.5.0a11
0.5.0a12
0.5.0a13
0.5.0a2
0.5.0a3
0.5.0a4
0.5.0a5
0.5.0a6
0.5.0a7
0.5.0a8
0.5.0a9
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.14
0.5.15
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.0a1
0.6.0a2
0.6.0a3
0.6.0a4
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
0.9.0rc0
0.9.1
0.9.2
0.9.3
References Updated Jun 09, 2026 · Source: OSV.dev |
0.6.0a2
pre
Dependencies (45)
+ 37 more |
|
0.6.0a1
pre
2 CVEs
CVE-2026-31233
PYSEC-2026-347
GHSA-r6hf-g5x6-7pv9
Jun 29, 2026
Guardrails AI contains a code injection vulnerability in its Hub package installation mechanism
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Guardrails AI thru 0.6.7 contains a code injection vulnerability (CWE-94) in its Hub package installation mechanism. When installing validator packages via guardrails hub install, the system retrieves a manifest from the Guardrails Hub and dynamically executes a script specified in the post_install field. The script path is constructed from untrusted manifest data and executed without proper validation or sanitization, allowing remote code execution. An attacker who can publish malicious packages to the Hub can inject arbitrary code that will be executed on any system where a victim installs the malicious package. Affected versions
0.1.0
0.1.0rc1
0.1.0rc2
0.1.0rc3
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
+ 72 more Show less
0.1.9
0.2.0
0.2.0a1
0.2.0a2
0.2.0a3
0.2.0a4
0.2.0a5
0.2.0a6
0.2.1
0.2.1a0
0.2.2
0.2.3
0.2.3a1
0.2.4
0.2.4a1
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.0a0
0.5.0a1
0.5.0a10
0.5.0a11
0.5.0a12
0.5.0a13
0.5.0a2
0.5.0a3
0.5.0a4
0.5.0a5
0.5.0a6
0.5.0a7
0.5.0a8
0.5.0a9
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.14
0.5.15
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.0a1
0.6.0a2
0.6.0a3
0.6.0a4
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-45758
PYSEC-2026-206
GHSA-xmpw-2vmm-p4p6
Jun 05, 2026
9.6
/ 10
Critical
Network
Low
None
Required
Changed
High
High
High
Guardrails AI is a Python framework that helps build AI applications. On May 11, 2026 at approximately 6:00 PM Pacific, an attacker published a malicious version of Affected versions
0.1.0
0.1.0rc1
0.1.0rc2
0.1.0rc3
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
+ 92 more Show less
0.1.9
0.10.0
0.10.0a0
0.10.0a1
0.10.0a2
0.10.0a3
0.10.0a4
0.10.0a5
0.2.0
0.2.0a1
0.2.0a2
0.2.0a3
0.2.0a4
0.2.0a5
0.2.0a6
0.2.1
0.2.1a0
0.2.2
0.2.3
0.2.3a1
0.2.4
0.2.4a1
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.0a0
0.5.0a1
0.5.0a10
0.5.0a11
0.5.0a12
0.5.0a13
0.5.0a2
0.5.0a3
0.5.0a4
0.5.0a5
0.5.0a6
0.5.0a7
0.5.0a8
0.5.0a9
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.14
0.5.15
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.0a1
0.6.0a2
0.6.0a3
0.6.0a4
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
0.9.0rc0
0.9.1
0.9.2
0.9.3
References Updated Jun 09, 2026 · Source: OSV.dev |
0.6.0a1
pre
Dependencies (45)
+ 37 more |
|
0.5.15
patch
2 CVEs
CVE-2026-31233
PYSEC-2026-347
GHSA-r6hf-g5x6-7pv9
Jun 29, 2026
Guardrails AI contains a code injection vulnerability in its Hub package installation mechanism
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Guardrails AI thru 0.6.7 contains a code injection vulnerability (CWE-94) in its Hub package installation mechanism. When installing validator packages via guardrails hub install, the system retrieves a manifest from the Guardrails Hub and dynamically executes a script specified in the post_install field. The script path is constructed from untrusted manifest data and executed without proper validation or sanitization, allowing remote code execution. An attacker who can publish malicious packages to the Hub can inject arbitrary code that will be executed on any system where a victim installs the malicious package. Affected versions
0.1.0
0.1.0rc1
0.1.0rc2
0.1.0rc3
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
+ 72 more Show less
0.1.9
0.2.0
0.2.0a1
0.2.0a2
0.2.0a3
0.2.0a4
0.2.0a5
0.2.0a6
0.2.1
0.2.1a0
0.2.2
0.2.3
0.2.3a1
0.2.4
0.2.4a1
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.0a0
0.5.0a1
0.5.0a10
0.5.0a11
0.5.0a12
0.5.0a13
0.5.0a2
0.5.0a3
0.5.0a4
0.5.0a5
0.5.0a6
0.5.0a7
0.5.0a8
0.5.0a9
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.14
0.5.15
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.0a1
0.6.0a2
0.6.0a3
0.6.0a4
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-45758
PYSEC-2026-206
GHSA-xmpw-2vmm-p4p6
Jun 05, 2026
9.6
/ 10
Critical
Network
Low
None
Required
Changed
High
High
High
Guardrails AI is a Python framework that helps build AI applications. On May 11, 2026 at approximately 6:00 PM Pacific, an attacker published a malicious version of Affected versions
0.1.0
0.1.0rc1
0.1.0rc2
0.1.0rc3
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
+ 92 more Show less
0.1.9
0.10.0
0.10.0a0
0.10.0a1
0.10.0a2
0.10.0a3
0.10.0a4
0.10.0a5
0.2.0
0.2.0a1
0.2.0a2
0.2.0a3
0.2.0a4
0.2.0a5
0.2.0a6
0.2.1
0.2.1a0
0.2.2
0.2.3
0.2.3a1
0.2.4
0.2.4a1
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.0a0
0.5.0a1
0.5.0a10
0.5.0a11
0.5.0a12
0.5.0a13
0.5.0a2
0.5.0a3
0.5.0a4
0.5.0a5
0.5.0a6
0.5.0a7
0.5.0a8
0.5.0a9
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.14
0.5.15
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.0a1
0.6.0a2
0.6.0a3
0.6.0a4
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
0.9.0rc0
0.9.1
0.9.2
0.9.3
References Updated Jun 09, 2026 · Source: OSV.dev |
0.5.15
patch
Dependencies (46)
+ 38 more |
|
0.5.14
patch
2 CVEs
CVE-2026-31233
PYSEC-2026-347
GHSA-r6hf-g5x6-7pv9
Jun 29, 2026
Guardrails AI contains a code injection vulnerability in its Hub package installation mechanism
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Guardrails AI thru 0.6.7 contains a code injection vulnerability (CWE-94) in its Hub package installation mechanism. When installing validator packages via guardrails hub install, the system retrieves a manifest from the Guardrails Hub and dynamically executes a script specified in the post_install field. The script path is constructed from untrusted manifest data and executed without proper validation or sanitization, allowing remote code execution. An attacker who can publish malicious packages to the Hub can inject arbitrary code that will be executed on any system where a victim installs the malicious package. Affected versions
0.1.0
0.1.0rc1
0.1.0rc2
0.1.0rc3
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
+ 72 more Show less
0.1.9
0.2.0
0.2.0a1
0.2.0a2
0.2.0a3
0.2.0a4
0.2.0a5
0.2.0a6
0.2.1
0.2.1a0
0.2.2
0.2.3
0.2.3a1
0.2.4
0.2.4a1
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.0a0
0.5.0a1
0.5.0a10
0.5.0a11
0.5.0a12
0.5.0a13
0.5.0a2
0.5.0a3
0.5.0a4
0.5.0a5
0.5.0a6
0.5.0a7
0.5.0a8
0.5.0a9
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.14
0.5.15
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.0a1
0.6.0a2
0.6.0a3
0.6.0a4
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-45758
PYSEC-2026-206
GHSA-xmpw-2vmm-p4p6
Jun 05, 2026
9.6
/ 10
Critical
Network
Low
None
Required
Changed
High
High
High
Guardrails AI is a Python framework that helps build AI applications. On May 11, 2026 at approximately 6:00 PM Pacific, an attacker published a malicious version of Affected versions
0.1.0
0.1.0rc1
0.1.0rc2
0.1.0rc3
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
+ 92 more Show less
0.1.9
0.10.0
0.10.0a0
0.10.0a1
0.10.0a2
0.10.0a3
0.10.0a4
0.10.0a5
0.2.0
0.2.0a1
0.2.0a2
0.2.0a3
0.2.0a4
0.2.0a5
0.2.0a6
0.2.1
0.2.1a0
0.2.2
0.2.3
0.2.3a1
0.2.4
0.2.4a1
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.0a0
0.5.0a1
0.5.0a10
0.5.0a11
0.5.0a12
0.5.0a13
0.5.0a2
0.5.0a3
0.5.0a4
0.5.0a5
0.5.0a6
0.5.0a7
0.5.0a8
0.5.0a9
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.14
0.5.15
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.0a1
0.6.0a2
0.6.0a3
0.6.0a4
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
0.9.0rc0
0.9.1
0.9.2
0.9.3
References Updated Jun 09, 2026 · Source: OSV.dev |
0.5.14
patch
Dependencies (46)
+ 38 more |
|
0.5.13
patch
2 CVEs
CVE-2026-31233
PYSEC-2026-347
GHSA-r6hf-g5x6-7pv9
Jun 29, 2026
Guardrails AI contains a code injection vulnerability in its Hub package installation mechanism
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Guardrails AI thru 0.6.7 contains a code injection vulnerability (CWE-94) in its Hub package installation mechanism. When installing validator packages via guardrails hub install, the system retrieves a manifest from the Guardrails Hub and dynamically executes a script specified in the post_install field. The script path is constructed from untrusted manifest data and executed without proper validation or sanitization, allowing remote code execution. An attacker who can publish malicious packages to the Hub can inject arbitrary code that will be executed on any system where a victim installs the malicious package. Affected versions
0.1.0
0.1.0rc1
0.1.0rc2
0.1.0rc3
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
+ 72 more Show less
0.1.9
0.2.0
0.2.0a1
0.2.0a2
0.2.0a3
0.2.0a4
0.2.0a5
0.2.0a6
0.2.1
0.2.1a0
0.2.2
0.2.3
0.2.3a1
0.2.4
0.2.4a1
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.0a0
0.5.0a1
0.5.0a10
0.5.0a11
0.5.0a12
0.5.0a13
0.5.0a2
0.5.0a3
0.5.0a4
0.5.0a5
0.5.0a6
0.5.0a7
0.5.0a8
0.5.0a9
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.14
0.5.15
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.0a1
0.6.0a2
0.6.0a3
0.6.0a4
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-45758
PYSEC-2026-206
GHSA-xmpw-2vmm-p4p6
Jun 05, 2026
9.6
/ 10
Critical
Network
Low
None
Required
Changed
High
High
High
Guardrails AI is a Python framework that helps build AI applications. On May 11, 2026 at approximately 6:00 PM Pacific, an attacker published a malicious version of Affected versions
0.1.0
0.1.0rc1
0.1.0rc2
0.1.0rc3
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
+ 92 more Show less
0.1.9
0.10.0
0.10.0a0
0.10.0a1
0.10.0a2
0.10.0a3
0.10.0a4
0.10.0a5
0.2.0
0.2.0a1
0.2.0a2
0.2.0a3
0.2.0a4
0.2.0a5
0.2.0a6
0.2.1
0.2.1a0
0.2.2
0.2.3
0.2.3a1
0.2.4
0.2.4a1
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.0a0
0.5.0a1
0.5.0a10
0.5.0a11
0.5.0a12
0.5.0a13
0.5.0a2
0.5.0a3
0.5.0a4
0.5.0a5
0.5.0a6
0.5.0a7
0.5.0a8
0.5.0a9
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.14
0.5.15
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.0a1
0.6.0a2
0.6.0a3
0.6.0a4
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
0.9.0rc0
0.9.1
0.9.2
0.9.3
References Updated Jun 09, 2026 · Source: OSV.dev |
0.5.13
patch
Dependencies (46)
+ 38 more |
|
0.5.12
patch
2 CVEs
CVE-2026-31233
PYSEC-2026-347
GHSA-r6hf-g5x6-7pv9
Jun 29, 2026
Guardrails AI contains a code injection vulnerability in its Hub package installation mechanism
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Guardrails AI thru 0.6.7 contains a code injection vulnerability (CWE-94) in its Hub package installation mechanism. When installing validator packages via guardrails hub install, the system retrieves a manifest from the Guardrails Hub and dynamically executes a script specified in the post_install field. The script path is constructed from untrusted manifest data and executed without proper validation or sanitization, allowing remote code execution. An attacker who can publish malicious packages to the Hub can inject arbitrary code that will be executed on any system where a victim installs the malicious package. Affected versions
0.1.0
0.1.0rc1
0.1.0rc2
0.1.0rc3
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
+ 72 more Show less
0.1.9
0.2.0
0.2.0a1
0.2.0a2
0.2.0a3
0.2.0a4
0.2.0a5
0.2.0a6
0.2.1
0.2.1a0
0.2.2
0.2.3
0.2.3a1
0.2.4
0.2.4a1
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.0a0
0.5.0a1
0.5.0a10
0.5.0a11
0.5.0a12
0.5.0a13
0.5.0a2
0.5.0a3
0.5.0a4
0.5.0a5
0.5.0a6
0.5.0a7
0.5.0a8
0.5.0a9
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.14
0.5.15
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.0a1
0.6.0a2
0.6.0a3
0.6.0a4
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-45758
PYSEC-2026-206
GHSA-xmpw-2vmm-p4p6
Jun 05, 2026
9.6
/ 10
Critical
Network
Low
None
Required
Changed
High
High
High
Guardrails AI is a Python framework that helps build AI applications. On May 11, 2026 at approximately 6:00 PM Pacific, an attacker published a malicious version of Affected versions
0.1.0
0.1.0rc1
0.1.0rc2
0.1.0rc3
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
+ 92 more Show less
0.1.9
0.10.0
0.10.0a0
0.10.0a1
0.10.0a2
0.10.0a3
0.10.0a4
0.10.0a5
0.2.0
0.2.0a1
0.2.0a2
0.2.0a3
0.2.0a4
0.2.0a5
0.2.0a6
0.2.1
0.2.1a0
0.2.2
0.2.3
0.2.3a1
0.2.4
0.2.4a1
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.0a0
0.5.0a1
0.5.0a10
0.5.0a11
0.5.0a12
0.5.0a13
0.5.0a2
0.5.0a3
0.5.0a4
0.5.0a5
0.5.0a6
0.5.0a7
0.5.0a8
0.5.0a9
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.14
0.5.15
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.0a1
0.6.0a2
0.6.0a3
0.6.0a4
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
0.9.0rc0
0.9.1
0.9.2
0.9.3
References Updated Jun 09, 2026 · Source: OSV.dev |
0.5.12
patch
Dependencies (46)
+ 38 more |
|
0.5.11
patch
2 CVEs
CVE-2026-31233
PYSEC-2026-347
GHSA-r6hf-g5x6-7pv9
Jun 29, 2026
Guardrails AI contains a code injection vulnerability in its Hub package installation mechanism
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Guardrails AI thru 0.6.7 contains a code injection vulnerability (CWE-94) in its Hub package installation mechanism. When installing validator packages via guardrails hub install, the system retrieves a manifest from the Guardrails Hub and dynamically executes a script specified in the post_install field. The script path is constructed from untrusted manifest data and executed without proper validation or sanitization, allowing remote code execution. An attacker who can publish malicious packages to the Hub can inject arbitrary code that will be executed on any system where a victim installs the malicious package. Affected versions
0.1.0
0.1.0rc1
0.1.0rc2
0.1.0rc3
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
+ 72 more Show less
0.1.9
0.2.0
0.2.0a1
0.2.0a2
0.2.0a3
0.2.0a4
0.2.0a5
0.2.0a6
0.2.1
0.2.1a0
0.2.2
0.2.3
0.2.3a1
0.2.4
0.2.4a1
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.0a0
0.5.0a1
0.5.0a10
0.5.0a11
0.5.0a12
0.5.0a13
0.5.0a2
0.5.0a3
0.5.0a4
0.5.0a5
0.5.0a6
0.5.0a7
0.5.0a8
0.5.0a9
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.14
0.5.15
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.0a1
0.6.0a2
0.6.0a3
0.6.0a4
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-45758
PYSEC-2026-206
GHSA-xmpw-2vmm-p4p6
Jun 05, 2026
9.6
/ 10
Critical
Network
Low
None
Required
Changed
High
High
High
Guardrails AI is a Python framework that helps build AI applications. On May 11, 2026 at approximately 6:00 PM Pacific, an attacker published a malicious version of Affected versions
0.1.0
0.1.0rc1
0.1.0rc2
0.1.0rc3
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
+ 92 more Show less
0.1.9
0.10.0
0.10.0a0
0.10.0a1
0.10.0a2
0.10.0a3
0.10.0a4
0.10.0a5
0.2.0
0.2.0a1
0.2.0a2
0.2.0a3
0.2.0a4
0.2.0a5
0.2.0a6
0.2.1
0.2.1a0
0.2.2
0.2.3
0.2.3a1
0.2.4
0.2.4a1
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.0a0
0.5.0a1
0.5.0a10
0.5.0a11
0.5.0a12
0.5.0a13
0.5.0a2
0.5.0a3
0.5.0a4
0.5.0a5
0.5.0a6
0.5.0a7
0.5.0a8
0.5.0a9
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.14
0.5.15
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.0a1
0.6.0a2
0.6.0a3
0.6.0a4
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
0.9.0rc0
0.9.1
0.9.2
0.9.3
References Updated Jun 09, 2026 · Source: OSV.dev |
0.5.11
patch
Dependencies (46)
+ 38 more |
|
0.5.10
patch
2 CVEs
CVE-2026-31233
PYSEC-2026-347
GHSA-r6hf-g5x6-7pv9
Jun 29, 2026
Guardrails AI contains a code injection vulnerability in its Hub package installation mechanism
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Guardrails AI thru 0.6.7 contains a code injection vulnerability (CWE-94) in its Hub package installation mechanism. When installing validator packages via guardrails hub install, the system retrieves a manifest from the Guardrails Hub and dynamically executes a script specified in the post_install field. The script path is constructed from untrusted manifest data and executed without proper validation or sanitization, allowing remote code execution. An attacker who can publish malicious packages to the Hub can inject arbitrary code that will be executed on any system where a victim installs the malicious package. Affected versions
0.1.0
0.1.0rc1
0.1.0rc2
0.1.0rc3
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
+ 72 more Show less
0.1.9
0.2.0
0.2.0a1
0.2.0a2
0.2.0a3
0.2.0a4
0.2.0a5
0.2.0a6
0.2.1
0.2.1a0
0.2.2
0.2.3
0.2.3a1
0.2.4
0.2.4a1
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.0a0
0.5.0a1
0.5.0a10
0.5.0a11
0.5.0a12
0.5.0a13
0.5.0a2
0.5.0a3
0.5.0a4
0.5.0a5
0.5.0a6
0.5.0a7
0.5.0a8
0.5.0a9
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.14
0.5.15
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.0a1
0.6.0a2
0.6.0a3
0.6.0a4
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-45758
PYSEC-2026-206
GHSA-xmpw-2vmm-p4p6
Jun 05, 2026
9.6
/ 10
Critical
Network
Low
None
Required
Changed
High
High
High
Guardrails AI is a Python framework that helps build AI applications. On May 11, 2026 at approximately 6:00 PM Pacific, an attacker published a malicious version of Affected versions
0.1.0
0.1.0rc1
0.1.0rc2
0.1.0rc3
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
+ 92 more Show less
0.1.9
0.10.0
0.10.0a0
0.10.0a1
0.10.0a2
0.10.0a3
0.10.0a4
0.10.0a5
0.2.0
0.2.0a1
0.2.0a2
0.2.0a3
0.2.0a4
0.2.0a5
0.2.0a6
0.2.1
0.2.1a0
0.2.2
0.2.3
0.2.3a1
0.2.4
0.2.4a1
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.0a0
0.5.0a1
0.5.0a10
0.5.0a11
0.5.0a12
0.5.0a13
0.5.0a2
0.5.0a3
0.5.0a4
0.5.0a5
0.5.0a6
0.5.0a7
0.5.0a8
0.5.0a9
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.14
0.5.15
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.0a1
0.6.0a2
0.6.0a3
0.6.0a4
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
0.9.0rc0
0.9.1
0.9.2
0.9.3
References Updated Jun 09, 2026 · Source: OSV.dev |
0.5.10
patch
Dependencies (45)
+ 37 more |
|
0.5.9
patch
3 CVEs
CVE-2024-45858
PYSEC-2026-1432
GHSA-w392-75q8-vr67
Jul 07, 2026
Guardrails has an arbitrary code execution vulnerability
Critical
Network
Low
None
An arbitrary code execution vulnerability exists in versions 0.2.9 up to 0.5.10 of the Guardrails AI Guardrails framework because of the way it validates XML files. If a victim user loads a maliciously crafted XML file containing Python code, the code will be passed to an eval function, causing it to execute on the user's machine. Affected versions
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
+ 23 more Show less
0.5.0a0
0.5.0a1
0.5.0a10
0.5.0a11
0.5.0a12
0.5.0a13
0.5.0a2
0.5.0a3
0.5.0a4
0.5.0a5
0.5.0a6
0.5.0a7
0.5.0a8
0.5.0a9
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
Fixed in
0.5.10
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-31233
PYSEC-2026-347
GHSA-r6hf-g5x6-7pv9
Jun 29, 2026
Guardrails AI contains a code injection vulnerability in its Hub package installation mechanism
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Guardrails AI thru 0.6.7 contains a code injection vulnerability (CWE-94) in its Hub package installation mechanism. When installing validator packages via guardrails hub install, the system retrieves a manifest from the Guardrails Hub and dynamically executes a script specified in the post_install field. The script path is constructed from untrusted manifest data and executed without proper validation or sanitization, allowing remote code execution. An attacker who can publish malicious packages to the Hub can inject arbitrary code that will be executed on any system where a victim installs the malicious package. Affected versions
0.1.0
0.1.0rc1
0.1.0rc2
0.1.0rc3
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
+ 72 more Show less
0.1.9
0.2.0
0.2.0a1
0.2.0a2
0.2.0a3
0.2.0a4
0.2.0a5
0.2.0a6
0.2.1
0.2.1a0
0.2.2
0.2.3
0.2.3a1
0.2.4
0.2.4a1
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.0a0
0.5.0a1
0.5.0a10
0.5.0a11
0.5.0a12
0.5.0a13
0.5.0a2
0.5.0a3
0.5.0a4
0.5.0a5
0.5.0a6
0.5.0a7
0.5.0a8
0.5.0a9
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.14
0.5.15
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.0a1
0.6.0a2
0.6.0a3
0.6.0a4
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-45758
PYSEC-2026-206
GHSA-xmpw-2vmm-p4p6
Jun 05, 2026
9.6
/ 10
Critical
Network
Low
None
Required
Changed
High
High
High
Guardrails AI is a Python framework that helps build AI applications. On May 11, 2026 at approximately 6:00 PM Pacific, an attacker published a malicious version of Affected versions
0.1.0
0.1.0rc1
0.1.0rc2
0.1.0rc3
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
+ 92 more Show less
0.1.9
0.10.0
0.10.0a0
0.10.0a1
0.10.0a2
0.10.0a3
0.10.0a4
0.10.0a5
0.2.0
0.2.0a1
0.2.0a2
0.2.0a3
0.2.0a4
0.2.0a5
0.2.0a6
0.2.1
0.2.1a0
0.2.2
0.2.3
0.2.3a1
0.2.4
0.2.4a1
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.0a0
0.5.0a1
0.5.0a10
0.5.0a11
0.5.0a12
0.5.0a13
0.5.0a2
0.5.0a3
0.5.0a4
0.5.0a5
0.5.0a6
0.5.0a7
0.5.0a8
0.5.0a9
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.14
0.5.15
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.0a1
0.6.0a2
0.6.0a3
0.6.0a4
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
0.9.0rc0
0.9.1
0.9.2
0.9.3
References Updated Jun 09, 2026 · Source: OSV.dev |
0.5.9
patch
Dependencies (44)
+ 36 more |
|
0.5.8
patch
3 CVEs
CVE-2024-45858
PYSEC-2026-1432
GHSA-w392-75q8-vr67
Jul 07, 2026
Guardrails has an arbitrary code execution vulnerability
Critical
Network
Low
None
An arbitrary code execution vulnerability exists in versions 0.2.9 up to 0.5.10 of the Guardrails AI Guardrails framework because of the way it validates XML files. If a victim user loads a maliciously crafted XML file containing Python code, the code will be passed to an eval function, causing it to execute on the user's machine. Affected versions
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
+ 23 more Show less
0.5.0a0
0.5.0a1
0.5.0a10
0.5.0a11
0.5.0a12
0.5.0a13
0.5.0a2
0.5.0a3
0.5.0a4
0.5.0a5
0.5.0a6
0.5.0a7
0.5.0a8
0.5.0a9
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
Fixed in
0.5.10
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-31233
PYSEC-2026-347
GHSA-r6hf-g5x6-7pv9
Jun 29, 2026
Guardrails AI contains a code injection vulnerability in its Hub package installation mechanism
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Guardrails AI thru 0.6.7 contains a code injection vulnerability (CWE-94) in its Hub package installation mechanism. When installing validator packages via guardrails hub install, the system retrieves a manifest from the Guardrails Hub and dynamically executes a script specified in the post_install field. The script path is constructed from untrusted manifest data and executed without proper validation or sanitization, allowing remote code execution. An attacker who can publish malicious packages to the Hub can inject arbitrary code that will be executed on any system where a victim installs the malicious package. Affected versions
0.1.0
0.1.0rc1
0.1.0rc2
0.1.0rc3
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
+ 72 more Show less
0.1.9
0.2.0
0.2.0a1
0.2.0a2
0.2.0a3
0.2.0a4
0.2.0a5
0.2.0a6
0.2.1
0.2.1a0
0.2.2
0.2.3
0.2.3a1
0.2.4
0.2.4a1
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.0a0
0.5.0a1
0.5.0a10
0.5.0a11
0.5.0a12
0.5.0a13
0.5.0a2
0.5.0a3
0.5.0a4
0.5.0a5
0.5.0a6
0.5.0a7
0.5.0a8
0.5.0a9
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.14
0.5.15
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.0a1
0.6.0a2
0.6.0a3
0.6.0a4
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-45758
PYSEC-2026-206
GHSA-xmpw-2vmm-p4p6
Jun 05, 2026
9.6
/ 10
Critical
Network
Low
None
Required
Changed
High
High
High
Guardrails AI is a Python framework that helps build AI applications. On May 11, 2026 at approximately 6:00 PM Pacific, an attacker published a malicious version of Affected versions
0.1.0
0.1.0rc1
0.1.0rc2
0.1.0rc3
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
+ 92 more Show less
0.1.9
0.10.0
0.10.0a0
0.10.0a1
0.10.0a2
0.10.0a3
0.10.0a4
0.10.0a5
0.2.0
0.2.0a1
0.2.0a2
0.2.0a3
0.2.0a4
0.2.0a5
0.2.0a6
0.2.1
0.2.1a0
0.2.2
0.2.3
0.2.3a1
0.2.4
0.2.4a1
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.0a0
0.5.0a1
0.5.0a10
0.5.0a11
0.5.0a12
0.5.0a13
0.5.0a2
0.5.0a3
0.5.0a4
0.5.0a5
0.5.0a6
0.5.0a7
0.5.0a8
0.5.0a9
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.14
0.5.15
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.0a1
0.6.0a2
0.6.0a3
0.6.0a4
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
0.9.0rc0
0.9.1
0.9.2
0.9.3
References Updated Jun 09, 2026 · Source: OSV.dev |
0.5.8
patch
Dependencies (44)
+ 36 more |
|
0.5.7
patch
3 CVEs
CVE-2024-45858
PYSEC-2026-1432
GHSA-w392-75q8-vr67
Jul 07, 2026
Guardrails has an arbitrary code execution vulnerability
Critical
Network
Low
None
An arbitrary code execution vulnerability exists in versions 0.2.9 up to 0.5.10 of the Guardrails AI Guardrails framework because of the way it validates XML files. If a victim user loads a maliciously crafted XML file containing Python code, the code will be passed to an eval function, causing it to execute on the user's machine. Affected versions
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
+ 23 more Show less
0.5.0a0
0.5.0a1
0.5.0a10
0.5.0a11
0.5.0a12
0.5.0a13
0.5.0a2
0.5.0a3
0.5.0a4
0.5.0a5
0.5.0a6
0.5.0a7
0.5.0a8
0.5.0a9
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
Fixed in
0.5.10
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-31233
PYSEC-2026-347
GHSA-r6hf-g5x6-7pv9
Jun 29, 2026
Guardrails AI contains a code injection vulnerability in its Hub package installation mechanism
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Guardrails AI thru 0.6.7 contains a code injection vulnerability (CWE-94) in its Hub package installation mechanism. When installing validator packages via guardrails hub install, the system retrieves a manifest from the Guardrails Hub and dynamically executes a script specified in the post_install field. The script path is constructed from untrusted manifest data and executed without proper validation or sanitization, allowing remote code execution. An attacker who can publish malicious packages to the Hub can inject arbitrary code that will be executed on any system where a victim installs the malicious package. Affected versions
0.1.0
0.1.0rc1
0.1.0rc2
0.1.0rc3
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
+ 72 more Show less
0.1.9
0.2.0
0.2.0a1
0.2.0a2
0.2.0a3
0.2.0a4
0.2.0a5
0.2.0a6
0.2.1
0.2.1a0
0.2.2
0.2.3
0.2.3a1
0.2.4
0.2.4a1
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.0a0
0.5.0a1
0.5.0a10
0.5.0a11
0.5.0a12
0.5.0a13
0.5.0a2
0.5.0a3
0.5.0a4
0.5.0a5
0.5.0a6
0.5.0a7
0.5.0a8
0.5.0a9
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.14
0.5.15
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.0a1
0.6.0a2
0.6.0a3
0.6.0a4
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-45758
PYSEC-2026-206
GHSA-xmpw-2vmm-p4p6
Jun 05, 2026
9.6
/ 10
Critical
Network
Low
None
Required
Changed
High
High
High
Guardrails AI is a Python framework that helps build AI applications. On May 11, 2026 at approximately 6:00 PM Pacific, an attacker published a malicious version of Affected versions
0.1.0
0.1.0rc1
0.1.0rc2
0.1.0rc3
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
+ 92 more Show less
0.1.9
0.10.0
0.10.0a0
0.10.0a1
0.10.0a2
0.10.0a3
0.10.0a4
0.10.0a5
0.2.0
0.2.0a1
0.2.0a2
0.2.0a3
0.2.0a4
0.2.0a5
0.2.0a6
0.2.1
0.2.1a0
0.2.2
0.2.3
0.2.3a1
0.2.4
0.2.4a1
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.0a0
0.5.0a1
0.5.0a10
0.5.0a11
0.5.0a12
0.5.0a13
0.5.0a2
0.5.0a3
0.5.0a4
0.5.0a5
0.5.0a6
0.5.0a7
0.5.0a8
0.5.0a9
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.14
0.5.15
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.0a1
0.6.0a2
0.6.0a3
0.6.0a4
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
0.9.0rc0
0.9.1
0.9.2
0.9.3
References Updated Jun 09, 2026 · Source: OSV.dev |
0.5.7
patch
Dependencies (43)
+ 35 more |
|
0.5.6
patch
3 CVEs
CVE-2024-45858
PYSEC-2026-1432
GHSA-w392-75q8-vr67
Jul 07, 2026
Guardrails has an arbitrary code execution vulnerability
Critical
Network
Low
None
An arbitrary code execution vulnerability exists in versions 0.2.9 up to 0.5.10 of the Guardrails AI Guardrails framework because of the way it validates XML files. If a victim user loads a maliciously crafted XML file containing Python code, the code will be passed to an eval function, causing it to execute on the user's machine. Affected versions
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
+ 23 more Show less
0.5.0a0
0.5.0a1
0.5.0a10
0.5.0a11
0.5.0a12
0.5.0a13
0.5.0a2
0.5.0a3
0.5.0a4
0.5.0a5
0.5.0a6
0.5.0a7
0.5.0a8
0.5.0a9
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
Fixed in
0.5.10
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-31233
PYSEC-2026-347
GHSA-r6hf-g5x6-7pv9
Jun 29, 2026
Guardrails AI contains a code injection vulnerability in its Hub package installation mechanism
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Guardrails AI thru 0.6.7 contains a code injection vulnerability (CWE-94) in its Hub package installation mechanism. When installing validator packages via guardrails hub install, the system retrieves a manifest from the Guardrails Hub and dynamically executes a script specified in the post_install field. The script path is constructed from untrusted manifest data and executed without proper validation or sanitization, allowing remote code execution. An attacker who can publish malicious packages to the Hub can inject arbitrary code that will be executed on any system where a victim installs the malicious package. Affected versions
0.1.0
0.1.0rc1
0.1.0rc2
0.1.0rc3
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
+ 72 more Show less
0.1.9
0.2.0
0.2.0a1
0.2.0a2
0.2.0a3
0.2.0a4
0.2.0a5
0.2.0a6
0.2.1
0.2.1a0
0.2.2
0.2.3
0.2.3a1
0.2.4
0.2.4a1
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.0a0
0.5.0a1
0.5.0a10
0.5.0a11
0.5.0a12
0.5.0a13
0.5.0a2
0.5.0a3
0.5.0a4
0.5.0a5
0.5.0a6
0.5.0a7
0.5.0a8
0.5.0a9
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.14
0.5.15
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.0a1
0.6.0a2
0.6.0a3
0.6.0a4
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-45758
PYSEC-2026-206
GHSA-xmpw-2vmm-p4p6
Jun 05, 2026
9.6
/ 10
Critical
Network
Low
None
Required
Changed
High
High
High
Guardrails AI is a Python framework that helps build AI applications. On May 11, 2026 at approximately 6:00 PM Pacific, an attacker published a malicious version of Affected versions
0.1.0
0.1.0rc1
0.1.0rc2
0.1.0rc3
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
+ 92 more Show less
0.1.9
0.10.0
0.10.0a0
0.10.0a1
0.10.0a2
0.10.0a3
0.10.0a4
0.10.0a5
0.2.0
0.2.0a1
0.2.0a2
0.2.0a3
0.2.0a4
0.2.0a5
0.2.0a6
0.2.1
0.2.1a0
0.2.2
0.2.3
0.2.3a1
0.2.4
0.2.4a1
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.0a0
0.5.0a1
0.5.0a10
0.5.0a11
0.5.0a12
0.5.0a13
0.5.0a2
0.5.0a3
0.5.0a4
0.5.0a5
0.5.0a6
0.5.0a7
0.5.0a8
0.5.0a9
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.14
0.5.15
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.0a1
0.6.0a2
0.6.0a3
0.6.0a4
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
0.9.0rc0
0.9.1
0.9.2
0.9.3
References Updated Jun 09, 2026 · Source: OSV.dev |
0.5.6
patch
Dependencies (42)
+ 34 more |
|
0.5.5
patch
3 CVEs
CVE-2024-45858
PYSEC-2026-1432
GHSA-w392-75q8-vr67
Jul 07, 2026
Guardrails has an arbitrary code execution vulnerability
Critical
Network
Low
None
An arbitrary code execution vulnerability exists in versions 0.2.9 up to 0.5.10 of the Guardrails AI Guardrails framework because of the way it validates XML files. If a victim user loads a maliciously crafted XML file containing Python code, the code will be passed to an eval function, causing it to execute on the user's machine. Affected versions
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
+ 23 more Show less
0.5.0a0
0.5.0a1
0.5.0a10
0.5.0a11
0.5.0a12
0.5.0a13
0.5.0a2
0.5.0a3
0.5.0a4
0.5.0a5
0.5.0a6
0.5.0a7
0.5.0a8
0.5.0a9
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
Fixed in
0.5.10
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-31233
PYSEC-2026-347
GHSA-r6hf-g5x6-7pv9
Jun 29, 2026
Guardrails AI contains a code injection vulnerability in its Hub package installation mechanism
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Guardrails AI thru 0.6.7 contains a code injection vulnerability (CWE-94) in its Hub package installation mechanism. When installing validator packages via guardrails hub install, the system retrieves a manifest from the Guardrails Hub and dynamically executes a script specified in the post_install field. The script path is constructed from untrusted manifest data and executed without proper validation or sanitization, allowing remote code execution. An attacker who can publish malicious packages to the Hub can inject arbitrary code that will be executed on any system where a victim installs the malicious package. Affected versions
0.1.0
0.1.0rc1
0.1.0rc2
0.1.0rc3
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
+ 72 more Show less
0.1.9
0.2.0
0.2.0a1
0.2.0a2
0.2.0a3
0.2.0a4
0.2.0a5
0.2.0a6
0.2.1
0.2.1a0
0.2.2
0.2.3
0.2.3a1
0.2.4
0.2.4a1
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.0a0
0.5.0a1
0.5.0a10
0.5.0a11
0.5.0a12
0.5.0a13
0.5.0a2
0.5.0a3
0.5.0a4
0.5.0a5
0.5.0a6
0.5.0a7
0.5.0a8
0.5.0a9
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.14
0.5.15
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.0a1
0.6.0a2
0.6.0a3
0.6.0a4
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-45758
PYSEC-2026-206
GHSA-xmpw-2vmm-p4p6
Jun 05, 2026
9.6
/ 10
Critical
Network
Low
None
Required
Changed
High
High
High
Guardrails AI is a Python framework that helps build AI applications. On May 11, 2026 at approximately 6:00 PM Pacific, an attacker published a malicious version of Affected versions
0.1.0
0.1.0rc1
0.1.0rc2
0.1.0rc3
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
+ 92 more Show less
0.1.9
0.10.0
0.10.0a0
0.10.0a1
0.10.0a2
0.10.0a3
0.10.0a4
0.10.0a5
0.2.0
0.2.0a1
0.2.0a2
0.2.0a3
0.2.0a4
0.2.0a5
0.2.0a6
0.2.1
0.2.1a0
0.2.2
0.2.3
0.2.3a1
0.2.4
0.2.4a1
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.0a0
0.5.0a1
0.5.0a10
0.5.0a11
0.5.0a12
0.5.0a13
0.5.0a2
0.5.0a3
0.5.0a4
0.5.0a5
0.5.0a6
0.5.0a7
0.5.0a8
0.5.0a9
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.14
0.5.15
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.0a1
0.6.0a2
0.6.0a3
0.6.0a4
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
0.9.0rc0
0.9.1
0.9.2
0.9.3
References Updated Jun 09, 2026 · Source: OSV.dev |
0.5.5
patch
Dependencies (42)
+ 34 more |
|
0.5.4
patch
3 CVEs
CVE-2024-45858
PYSEC-2026-1432
GHSA-w392-75q8-vr67
Jul 07, 2026
Guardrails has an arbitrary code execution vulnerability
Critical
Network
Low
None
An arbitrary code execution vulnerability exists in versions 0.2.9 up to 0.5.10 of the Guardrails AI Guardrails framework because of the way it validates XML files. If a victim user loads a maliciously crafted XML file containing Python code, the code will be passed to an eval function, causing it to execute on the user's machine. Affected versions
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
+ 23 more Show less
0.5.0a0
0.5.0a1
0.5.0a10
0.5.0a11
0.5.0a12
0.5.0a13
0.5.0a2
0.5.0a3
0.5.0a4
0.5.0a5
0.5.0a6
0.5.0a7
0.5.0a8
0.5.0a9
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
Fixed in
0.5.10
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-31233
PYSEC-2026-347
GHSA-r6hf-g5x6-7pv9
Jun 29, 2026
Guardrails AI contains a code injection vulnerability in its Hub package installation mechanism
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Guardrails AI thru 0.6.7 contains a code injection vulnerability (CWE-94) in its Hub package installation mechanism. When installing validator packages via guardrails hub install, the system retrieves a manifest from the Guardrails Hub and dynamically executes a script specified in the post_install field. The script path is constructed from untrusted manifest data and executed without proper validation or sanitization, allowing remote code execution. An attacker who can publish malicious packages to the Hub can inject arbitrary code that will be executed on any system where a victim installs the malicious package. Affected versions
0.1.0
0.1.0rc1
0.1.0rc2
0.1.0rc3
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
+ 72 more Show less
0.1.9
0.2.0
0.2.0a1
0.2.0a2
0.2.0a3
0.2.0a4
0.2.0a5
0.2.0a6
0.2.1
0.2.1a0
0.2.2
0.2.3
0.2.3a1
0.2.4
0.2.4a1
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.0a0
0.5.0a1
0.5.0a10
0.5.0a11
0.5.0a12
0.5.0a13
0.5.0a2
0.5.0a3
0.5.0a4
0.5.0a5
0.5.0a6
0.5.0a7
0.5.0a8
0.5.0a9
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.14
0.5.15
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.0a1
0.6.0a2
0.6.0a3
0.6.0a4
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-45758
PYSEC-2026-206
GHSA-xmpw-2vmm-p4p6
Jun 05, 2026
9.6
/ 10
Critical
Network
Low
None
Required
Changed
High
High
High
Guardrails AI is a Python framework that helps build AI applications. On May 11, 2026 at approximately 6:00 PM Pacific, an attacker published a malicious version of Affected versions
0.1.0
0.1.0rc1
0.1.0rc2
0.1.0rc3
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
+ 92 more Show less
0.1.9
0.10.0
0.10.0a0
0.10.0a1
0.10.0a2
0.10.0a3
0.10.0a4
0.10.0a5
0.2.0
0.2.0a1
0.2.0a2
0.2.0a3
0.2.0a4
0.2.0a5
0.2.0a6
0.2.1
0.2.1a0
0.2.2
0.2.3
0.2.3a1
0.2.4
0.2.4a1
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.0a0
0.5.0a1
0.5.0a10
0.5.0a11
0.5.0a12
0.5.0a13
0.5.0a2
0.5.0a3
0.5.0a4
0.5.0a5
0.5.0a6
0.5.0a7
0.5.0a8
0.5.0a9
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.14
0.5.15
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.0a1
0.6.0a2
0.6.0a3
0.6.0a4
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
0.9.0rc0
0.9.1
0.9.2
0.9.3
References Updated Jun 09, 2026 · Source: OSV.dev |
0.5.4
patch
Dependencies (42)
+ 34 more |
|
0.5.3
patch
3 CVEs
CVE-2024-45858
PYSEC-2026-1432
GHSA-w392-75q8-vr67
Jul 07, 2026
Guardrails has an arbitrary code execution vulnerability
Critical
Network
Low
None
An arbitrary code execution vulnerability exists in versions 0.2.9 up to 0.5.10 of the Guardrails AI Guardrails framework because of the way it validates XML files. If a victim user loads a maliciously crafted XML file containing Python code, the code will be passed to an eval function, causing it to execute on the user's machine. Affected versions
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
+ 23 more Show less
0.5.0a0
0.5.0a1
0.5.0a10
0.5.0a11
0.5.0a12
0.5.0a13
0.5.0a2
0.5.0a3
0.5.0a4
0.5.0a5
0.5.0a6
0.5.0a7
0.5.0a8
0.5.0a9
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
Fixed in
0.5.10
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-31233
PYSEC-2026-347
GHSA-r6hf-g5x6-7pv9
Jun 29, 2026
Guardrails AI contains a code injection vulnerability in its Hub package installation mechanism
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Guardrails AI thru 0.6.7 contains a code injection vulnerability (CWE-94) in its Hub package installation mechanism. When installing validator packages via guardrails hub install, the system retrieves a manifest from the Guardrails Hub and dynamically executes a script specified in the post_install field. The script path is constructed from untrusted manifest data and executed without proper validation or sanitization, allowing remote code execution. An attacker who can publish malicious packages to the Hub can inject arbitrary code that will be executed on any system where a victim installs the malicious package. Affected versions
0.1.0
0.1.0rc1
0.1.0rc2
0.1.0rc3
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
+ 72 more Show less
0.1.9
0.2.0
0.2.0a1
0.2.0a2
0.2.0a3
0.2.0a4
0.2.0a5
0.2.0a6
0.2.1
0.2.1a0
0.2.2
0.2.3
0.2.3a1
0.2.4
0.2.4a1
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.0a0
0.5.0a1
0.5.0a10
0.5.0a11
0.5.0a12
0.5.0a13
0.5.0a2
0.5.0a3
0.5.0a4
0.5.0a5
0.5.0a6
0.5.0a7
0.5.0a8
0.5.0a9
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.14
0.5.15
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.0a1
0.6.0a2
0.6.0a3
0.6.0a4
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-45758
PYSEC-2026-206
GHSA-xmpw-2vmm-p4p6
Jun 05, 2026
9.6
/ 10
Critical
Network
Low
None
Required
Changed
High
High
High
Guardrails AI is a Python framework that helps build AI applications. On May 11, 2026 at approximately 6:00 PM Pacific, an attacker published a malicious version of Affected versions
0.1.0
0.1.0rc1
0.1.0rc2
0.1.0rc3
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
+ 92 more Show less
0.1.9
0.10.0
0.10.0a0
0.10.0a1
0.10.0a2
0.10.0a3
0.10.0a4
0.10.0a5
0.2.0
0.2.0a1
0.2.0a2
0.2.0a3
0.2.0a4
0.2.0a5
0.2.0a6
0.2.1
0.2.1a0
0.2.2
0.2.3
0.2.3a1
0.2.4
0.2.4a1
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.0a0
0.5.0a1
0.5.0a10
0.5.0a11
0.5.0a12
0.5.0a13
0.5.0a2
0.5.0a3
0.5.0a4
0.5.0a5
0.5.0a6
0.5.0a7
0.5.0a8
0.5.0a9
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.14
0.5.15
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.0a1
0.6.0a2
0.6.0a3
0.6.0a4
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
0.9.0rc0
0.9.1
0.9.2
0.9.3
References Updated Jun 09, 2026 · Source: OSV.dev |
0.5.3
patch
Dependencies (41)
+ 33 more |
|
0.5.2
patch
3 CVEs
CVE-2024-45858
PYSEC-2026-1432
GHSA-w392-75q8-vr67
Jul 07, 2026
Guardrails has an arbitrary code execution vulnerability
Critical
Network
Low
None
An arbitrary code execution vulnerability exists in versions 0.2.9 up to 0.5.10 of the Guardrails AI Guardrails framework because of the way it validates XML files. If a victim user loads a maliciously crafted XML file containing Python code, the code will be passed to an eval function, causing it to execute on the user's machine. Affected versions
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
+ 23 more Show less
0.5.0a0
0.5.0a1
0.5.0a10
0.5.0a11
0.5.0a12
0.5.0a13
0.5.0a2
0.5.0a3
0.5.0a4
0.5.0a5
0.5.0a6
0.5.0a7
0.5.0a8
0.5.0a9
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
Fixed in
0.5.10
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-31233
PYSEC-2026-347
GHSA-r6hf-g5x6-7pv9
Jun 29, 2026
Guardrails AI contains a code injection vulnerability in its Hub package installation mechanism
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Guardrails AI thru 0.6.7 contains a code injection vulnerability (CWE-94) in its Hub package installation mechanism. When installing validator packages via guardrails hub install, the system retrieves a manifest from the Guardrails Hub and dynamically executes a script specified in the post_install field. The script path is constructed from untrusted manifest data and executed without proper validation or sanitization, allowing remote code execution. An attacker who can publish malicious packages to the Hub can inject arbitrary code that will be executed on any system where a victim installs the malicious package. Affected versions
0.1.0
0.1.0rc1
0.1.0rc2
0.1.0rc3
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
+ 72 more Show less
0.1.9
0.2.0
0.2.0a1
0.2.0a2
0.2.0a3
0.2.0a4
0.2.0a5
0.2.0a6
0.2.1
0.2.1a0
0.2.2
0.2.3
0.2.3a1
0.2.4
0.2.4a1
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.0a0
0.5.0a1
0.5.0a10
0.5.0a11
0.5.0a12
0.5.0a13
0.5.0a2
0.5.0a3
0.5.0a4
0.5.0a5
0.5.0a6
0.5.0a7
0.5.0a8
0.5.0a9
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.14
0.5.15
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.0a1
0.6.0a2
0.6.0a3
0.6.0a4
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-45758
PYSEC-2026-206
GHSA-xmpw-2vmm-p4p6
Jun 05, 2026
9.6
/ 10
Critical
Network
Low
None
Required
Changed
High
High
High
Guardrails AI is a Python framework that helps build AI applications. On May 11, 2026 at approximately 6:00 PM Pacific, an attacker published a malicious version of Affected versions
0.1.0
0.1.0rc1
0.1.0rc2
0.1.0rc3
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
+ 92 more Show less
0.1.9
0.10.0
0.10.0a0
0.10.0a1
0.10.0a2
0.10.0a3
0.10.0a4
0.10.0a5
0.2.0
0.2.0a1
0.2.0a2
0.2.0a3
0.2.0a4
0.2.0a5
0.2.0a6
0.2.1
0.2.1a0
0.2.2
0.2.3
0.2.3a1
0.2.4
0.2.4a1
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.0a0
0.5.0a1
0.5.0a10
0.5.0a11
0.5.0a12
0.5.0a13
0.5.0a2
0.5.0a3
0.5.0a4
0.5.0a5
0.5.0a6
0.5.0a7
0.5.0a8
0.5.0a9
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.14
0.5.15
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.0a1
0.6.0a2
0.6.0a3
0.6.0a4
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
0.9.0rc0
0.9.1
0.9.2
0.9.3
References Updated Jun 09, 2026 · Source: OSV.dev |
0.5.2
patch
Dependencies (41)
+ 33 more |
|
0.5.1
patch
3 CVEs
CVE-2024-45858
PYSEC-2026-1432
GHSA-w392-75q8-vr67
Jul 07, 2026
Guardrails has an arbitrary code execution vulnerability
Critical
Network
Low
None
An arbitrary code execution vulnerability exists in versions 0.2.9 up to 0.5.10 of the Guardrails AI Guardrails framework because of the way it validates XML files. If a victim user loads a maliciously crafted XML file containing Python code, the code will be passed to an eval function, causing it to execute on the user's machine. Affected versions
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
+ 23 more Show less
0.5.0a0
0.5.0a1
0.5.0a10
0.5.0a11
0.5.0a12
0.5.0a13
0.5.0a2
0.5.0a3
0.5.0a4
0.5.0a5
0.5.0a6
0.5.0a7
0.5.0a8
0.5.0a9
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
Fixed in
0.5.10
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-31233
PYSEC-2026-347
GHSA-r6hf-g5x6-7pv9
Jun 29, 2026
Guardrails AI contains a code injection vulnerability in its Hub package installation mechanism
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Guardrails AI thru 0.6.7 contains a code injection vulnerability (CWE-94) in its Hub package installation mechanism. When installing validator packages via guardrails hub install, the system retrieves a manifest from the Guardrails Hub and dynamically executes a script specified in the post_install field. The script path is constructed from untrusted manifest data and executed without proper validation or sanitization, allowing remote code execution. An attacker who can publish malicious packages to the Hub can inject arbitrary code that will be executed on any system where a victim installs the malicious package. Affected versions
0.1.0
0.1.0rc1
0.1.0rc2
0.1.0rc3
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
+ 72 more Show less
0.1.9
0.2.0
0.2.0a1
0.2.0a2
0.2.0a3
0.2.0a4
0.2.0a5
0.2.0a6
0.2.1
0.2.1a0
0.2.2
0.2.3
0.2.3a1
0.2.4
0.2.4a1
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.0a0
0.5.0a1
0.5.0a10
0.5.0a11
0.5.0a12
0.5.0a13
0.5.0a2
0.5.0a3
0.5.0a4
0.5.0a5
0.5.0a6
0.5.0a7
0.5.0a8
0.5.0a9
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.14
0.5.15
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.0a1
0.6.0a2
0.6.0a3
0.6.0a4
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-45758
PYSEC-2026-206
GHSA-xmpw-2vmm-p4p6
Jun 05, 2026
9.6
/ 10
Critical
Network
Low
None
Required
Changed
High
High
High
Guardrails AI is a Python framework that helps build AI applications. On May 11, 2026 at approximately 6:00 PM Pacific, an attacker published a malicious version of Affected versions
0.1.0
0.1.0rc1
0.1.0rc2
0.1.0rc3
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
+ 92 more Show less
0.1.9
0.10.0
0.10.0a0
0.10.0a1
0.10.0a2
0.10.0a3
0.10.0a4
0.10.0a5
0.2.0
0.2.0a1
0.2.0a2
0.2.0a3
0.2.0a4
0.2.0a5
0.2.0a6
0.2.1
0.2.1a0
0.2.2
0.2.3
0.2.3a1
0.2.4
0.2.4a1
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.0a0
0.5.0a1
0.5.0a10
0.5.0a11
0.5.0a12
0.5.0a13
0.5.0a2
0.5.0a3
0.5.0a4
0.5.0a5
0.5.0a6
0.5.0a7
0.5.0a8
0.5.0a9
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.14
0.5.15
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.0a1
0.6.0a2
0.6.0a3
0.6.0a4
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
0.9.0rc0
0.9.1
0.9.2
0.9.3
References Updated Jun 09, 2026 · Source: OSV.dev |
0.5.1
patch
Dependencies (41)
+ 33 more |
|
0.5.0
minor
3 CVEs
CVE-2024-45858
PYSEC-2026-1432
GHSA-w392-75q8-vr67
Jul 07, 2026
Guardrails has an arbitrary code execution vulnerability
Critical
Network
Low
None
An arbitrary code execution vulnerability exists in versions 0.2.9 up to 0.5.10 of the Guardrails AI Guardrails framework because of the way it validates XML files. If a victim user loads a maliciously crafted XML file containing Python code, the code will be passed to an eval function, causing it to execute on the user's machine. Affected versions
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
+ 23 more Show less
0.5.0a0
0.5.0a1
0.5.0a10
0.5.0a11
0.5.0a12
0.5.0a13
0.5.0a2
0.5.0a3
0.5.0a4
0.5.0a5
0.5.0a6
0.5.0a7
0.5.0a8
0.5.0a9
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
Fixed in
0.5.10
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-31233
PYSEC-2026-347
GHSA-r6hf-g5x6-7pv9
Jun 29, 2026
Guardrails AI contains a code injection vulnerability in its Hub package installation mechanism
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Guardrails AI thru 0.6.7 contains a code injection vulnerability (CWE-94) in its Hub package installation mechanism. When installing validator packages via guardrails hub install, the system retrieves a manifest from the Guardrails Hub and dynamically executes a script specified in the post_install field. The script path is constructed from untrusted manifest data and executed without proper validation or sanitization, allowing remote code execution. An attacker who can publish malicious packages to the Hub can inject arbitrary code that will be executed on any system where a victim installs the malicious package. Affected versions
0.1.0
0.1.0rc1
0.1.0rc2
0.1.0rc3
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
+ 72 more Show less
0.1.9
0.2.0
0.2.0a1
0.2.0a2
0.2.0a3
0.2.0a4
0.2.0a5
0.2.0a6
0.2.1
0.2.1a0
0.2.2
0.2.3
0.2.3a1
0.2.4
0.2.4a1
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.0a0
0.5.0a1
0.5.0a10
0.5.0a11
0.5.0a12
0.5.0a13
0.5.0a2
0.5.0a3
0.5.0a4
0.5.0a5
0.5.0a6
0.5.0a7
0.5.0a8
0.5.0a9
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.14
0.5.15
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.0a1
0.6.0a2
0.6.0a3
0.6.0a4
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-45758
PYSEC-2026-206
GHSA-xmpw-2vmm-p4p6
Jun 05, 2026
9.6
/ 10
Critical
Network
Low
None
Required
Changed
High
High
High
Guardrails AI is a Python framework that helps build AI applications. On May 11, 2026 at approximately 6:00 PM Pacific, an attacker published a malicious version of Affected versions
0.1.0
0.1.0rc1
0.1.0rc2
0.1.0rc3
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
+ 92 more Show less
0.1.9
0.10.0
0.10.0a0
0.10.0a1
0.10.0a2
0.10.0a3
0.10.0a4
0.10.0a5
0.2.0
0.2.0a1
0.2.0a2
0.2.0a3
0.2.0a4
0.2.0a5
0.2.0a6
0.2.1
0.2.1a0
0.2.2
0.2.3
0.2.3a1
0.2.4
0.2.4a1
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.0a0
0.5.0a1
0.5.0a10
0.5.0a11
0.5.0a12
0.5.0a13
0.5.0a2
0.5.0a3
0.5.0a4
0.5.0a5
0.5.0a6
0.5.0a7
0.5.0a8
0.5.0a9
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.14
0.5.15
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.0a1
0.6.0a2
0.6.0a3
0.6.0a4
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.8.2
0.9.0
0.9.0rc0
0.9.1
0.9.2
0.9.3
References Updated Jun 09, 2026 · Source: OSV.dev |
0.5.0
minor
Dependencies (41)
+ 33 more |