Skip to content
BentoMLGHSA-564p-rx2q-4c8v

BentoML Open Redirect vulnerability

Medium6.1Published Mar 20, 2025 · updated Apr 15, 2025

An open redirect vulnerability in bentoml/bentoml v1.3.9 allows a remote unauthenticated attacker to redirect users to arbitrary websites via a specially crafted URL. This can be exploited for phishing attacks, malware distribution, and credential theft.

GitHub advisory

Affected versions

PackageAffectedFixed in
bentoml
PyPI
<= 1.3.9No fix yet
Details and references

More BentoML advisories

All BentoML
Advisory
BentoML SSRF Vulnerability in File Upload Processing
Critical9.9Jul 29, 2025
BentoML's runner server Vulnerable to Remote Code Execution (RCE) via Insecure Deserialization
Critical9.8Apr 9, 2025
BentoML Allows Remote Code Execution (RCE) via Insecure Deserialization
Critical9.8Apr 4, 2025
BentoML deserialization vulnerability
Critical9.8Mar 20, 2025
BentoML Denial of Service (DoS) via Multipart Boundary
High7.5Mar 20, 2025
BentoML vulnerable to Uncontrolled Resource Consumption
High7.5Mar 20, 2025

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.