Skip to content

BentoML security advisories

17 advisories · 8 critical or high in 12 months · latest Jul 8

17 advisories

DateAdvisory
Jul 8A vulnerability was found in bentoml OpenLLM 0.6.30. This affects the function async_run_command of the file src/openllm/common.py of the component Model Repository Directory Name Handler. Performing a manipulation of the argument cmd results in command injection. Attacking locally is a requirement.
CVE-2026-15035High7.8no fix yet
May 11Dockerfile command injection via envs[*].name in bentofile.yaml (sibling fix-bypass of CVE-2026-33744 and CVE-2026-35043)
CVE-2026-44346High8.8fixed in 1.4.39
May 11BentoML Dockerfile command injection via docker.base_image (sister of pending GHSA-w2pm-x38x-jp44 / CVE-2026-33744 / CVE-2026-35043)
CVE-2026-44345High8.8fixed in 1.4.39
May 7BentoML has Information Disclosure in `bentoml build` via symlink traversal in the build context
CVE-2026-40610Medium5.5fixed in 1.4.39
Apr 3BentoML: SSTI via Unsandboxed Jinja2 in Dockerfile Generation
CVE-2026-35044High8.8fixed in 1.4.38
Apr 3BentoML: Command Injection in cloud deployment setup script
CVE-2026-35043High7.8fixed in 1.4.38
Mar 26BentoML has Dockerfile Command Injection via system_packages in bentofile.yaml
CVE-2026-33744High7.8fixed in 1.4.37
Mar 3BentoML Vulnerable to Arbitrary File Write via Symlink Path Traversal in Tar Extraction
CVE-2026-27905Highfixed in 1.4.36
Jan 26BentoML has a Path Traversal via Bentofile Configuration
CVE-2026-24123High7.4fixed in 1.4.34
Jul 292025BentoML SSRF Vulnerability in File Upload Processing
CVE-2025-54381Critical9.9fixed in 1.4.19
Apr 92025BentoML's runner server Vulnerable to Remote Code Execution (RCE) via Insecure Deserialization
CVE-2025-32375Critical9.8fixed in 1.4.8
Apr 42025BentoML Allows Remote Code Execution (RCE) via Insecure Deserialization
CVE-2025-27520Critical9.8fixed in 1.4.3
Mar 202025BentoML deserialization vulnerability
CVE-2024-9070Critical9.8no fix yet
Mar 202025BentoML Denial of Service (DoS) via Multipart Boundary
CVE-2024-9056High7.5no fix yet
Mar 202025BentoML Open Redirect vulnerability
GHSA-564p-rx2q-4c8vMedium6.1no fix yet
Mar 202025BentoML vulnerable to Uncontrolled Resource Consumption
GHSA-hh3j-9m59-p8vcHigh7.5no fix yet
Apr 162024Insecure deserialization in BentoML
CVE-2024-2912Critical9.8fixed in 1.2.5
About BentoML

Build and serve model APIs.

Packages watched: bentoml (PyPI).

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.