PT-2026-39664 · Pypi · Bentoml

Ssjcorpsec

·

Published

2026-05-11

·

Updated

2026-06-02

·

CVE-2026-44346

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions BentoML versions prior to 1.4.39
Description BentoML is a Python library used for building online serving systems optimized for AI applications and model inference. A flaw exists where a malicious bentofile.yaml file containing a newline-injected value in the envs[*].name variable can produce unquoted RUN directives in the generated Dockerfile. When the bentoml containerize command is executed on the imported bento, these RUN directives are executed on the host system during the docker build process.
Recommendations Update to version 1.4.39.

Exploit

Fix

Code Injection

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-44346
GHSA-W2PM-X38X-JP44
PYSEC-2026-190

Affected Products

Bentoml