A vulnerability was found in bentoml OpenLLM 0.6.30. This affects the function async_run_command of the file src/openllm/common.py of the component Model Repository Directory Name Handler. Performing a manipulation of the argument cmd results in command injection. Attacking locally is a requirement. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet.
References
| Link | Resource |
|---|---|
| https://github.com/bentoml/OpenLLM/ | Product |
| https://github.com/bentoml/OpenLLM/issues/1229 | Exploit Patch Third Party Advisory |
| https://github.com/bentoml/OpenLLM/pull/1235 | Exploit Patch |
| https://vuldb.com/cve/CVE-2026-15035 | Third Party Advisory VDB Entry |
| https://vuldb.com/submit/850895 | Exploit Third Party Advisory VDB Entry |
| https://vuldb.com/vuln/376786 | Third Party Advisory VDB Entry |
| https://vuldb.com/vuln/376786/cti | Permissions Required |
Configurations
History
09 Jul 2026, 15:54
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/bentoml/OpenLLM/ - Product | |
| References | () https://github.com/bentoml/OpenLLM/issues/1229 - Exploit, Patch, Third Party Advisory | |
| References | () https://github.com/bentoml/OpenLLM/pull/1235 - Exploit, Patch | |
| References | () https://vuldb.com/cve/CVE-2026-15035 - Third Party Advisory, VDB Entry | |
| References | () https://vuldb.com/submit/850895 - Exploit, Third Party Advisory, VDB Entry | |
| References | () https://vuldb.com/vuln/376786 - Third Party Advisory, VDB Entry | |
| References | () https://vuldb.com/vuln/376786/cti - Permissions Required | |
| CPE | cpe:2.3:a:bentoml:openllm:0.6.30:*:*:*:*:*:*:* | |
| First Time |
Bentoml openllm
Bentoml |
|
| CWE | CWE-78 |
08 Jul 2026, 14:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-07-08 14:16
Updated : 2026-07-09 15:54
NVD link : CVE-2026-15035
Mitre link : CVE-2026-15035
CVE.ORG link : CVE-2026-15035
JSON object : View
Products Affected
bentoml
- openllm
