guardrails-ai
PyPI Compromised1
report
Attack type: Malicious version
Reports
Malicious version CVE-2026-45758 Versions: = 0.10.1 10d ago by isitcompromised.com
Malicious code in guardrails-ai 0.10.1 (supply chain compromise) ### Impact On May 11, 2026 at approximately 6:00 PM Pacific, an attacker published a malicious version of `guardrails-ai` (0.10.1) to PyPI. **Affected:** any user who installed `guardrails-ai==0.10.1` from PyPI on May 11, 2026. Security researchers identified the malicious package within approximately 2 hours of publication, and PyPI quarantined the repository. Based on our telemetry, we have observed no requests to Guardrails AI infrastructure originating from the malicious 0.10.1 version, a
View evidence