Arbitrary Code Execution in BentoML Python Library for AI Applications
CVE-2026-44345

8.8HIGH

Key Information:

Vendor

Bentoml

Status
Vendor
CVE Published:
27 May 2026

What is CVE-2026-44345?

BentoML, a Python library designed for building optimized online serving systems for AI applications, contains a vulnerability that allows attackers to exploit improper handling of Dockerfile templates. Specifically, prior to version 1.4.39, the affected Dockerfile template does not escape or validate multi-line inputs from a bento.yaml file. This flaw can lead to the injection of arbitrary Dockerfile directives into the generated Dockerfile, enabling malicious users to execute unauthorized commands on the host system during the containerization process. Users are advised to update to version 1.4.39 or later to mitigate this risk.

Affected Version(s)

BentoML < 1.4.39

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.