Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-24123

Опубликовано: 26 янв. 2026
Источник: nvd
CVSS3: 7.4
CVSS3: 6.5
EPSS Низкий

Описание

BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to version 1.4.34, BentoML's bentofile.yaml configuration allows path traversal attacks through multiple file path fields (description, docker.setup_script, docker.dockerfile_template, conda.environment_yml). An attacker can craft a malicious bentofile that, when built by a victim, exfiltrates arbitrary files from the filesystem into the bento archive. This enables supply chain attacks where sensitive files (SSH keys, credentials, environment variables) are silently embedded in bentos and exposed when pushed to registries or deployed. Version 1.4.34 contains a patch for the issue.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:bentoml:bentoml:*:*:*:*:*:*:*:*
Версия до 1.4.34 (исключая)

EPSS

Процентиль: 1%
0.0001
Низкий

7.4 High

CVSS3

6.5 Medium

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 7.4
github
12 дней назад

BentoML has a Path Traversal via Bentofile Configuration

EPSS

Процентиль: 1%
0.0001
Низкий

7.4 High

CVSS3

6.5 Medium

CVSS3

Дефекты

CWE-22