CVE-2026-24123

BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to version 1.4.34, BentoML's `bentofile.yaml` configuration allows path traversal attacks through multiple file path fields (`description`, `docker.setup_script`, `docker.dockerfile_template`, `conda.environment_yml`). An attacker can craft a malicious bentofile that, when built by a victim, exfiltrates arbitrary files from the filesystem into the bento archive. This enables supply chain attacks where sensitive files (SSH keys, credentials, environment variables) are silently embedded in bentos and exposed when pushed to registries or deployed. Version 1.4.34 contains a patch for the issue.
Configurations

Configuration 1 (hide)

cpe:2.3:a:bentoml:bentoml:*:*:*:*:*:*:*:*

History

17 Jun 2026, 10:22

Type Values Removed Values Added
Summary
  • (es) BentoML es una librería de Python para construir sistemas de servicio en línea optimizados para aplicaciones de IA e inferencia de modelos. Antes de la versión 1.4.34, la configuración `bentofile.yaml` de BentoML permite ataques de salto de ruta a través de múltiples campos de ruta de archivo (`description`, `docker.setup_script`, `docker.dockerfile_template`, `conda.environment_yml`). Un atacante puede crear un bentofile malicioso que, cuando es construido por una víctima, exfiltra archivos arbitrarios del sistema de archivos al archivo bento. Esto permite ataques a la cadena de suministro donde archivos sensibles (claves SSH, credenciales, variables de entorno) son incrustados silenciosamente en los bentos y expuestos cuando se suben a registros o se despliegan. La versión 1.4.34 contiene un parche para el problema.

03 Feb 2026, 15:07

Type Values Removed Values Added
References () https://github.com/bentoml/BentoML/commit/84d08cfeb40c5f2ce71b3d3444bbaa0fb16b5ca4 - () https://github.com/bentoml/BentoML/commit/84d08cfeb40c5f2ce71b3d3444bbaa0fb16b5ca4 - Patch
References () https://github.com/bentoml/BentoML/releases/tag/v1.4.34 - () https://github.com/bentoml/BentoML/releases/tag/v1.4.34 - Product, Release Notes
References () https://github.com/bentoml/BentoML/security/advisories/GHSA-6r62-w2q3-48hf - () https://github.com/bentoml/BentoML/security/advisories/GHSA-6r62-w2q3-48hf - Vendor Advisory
First Time Bentoml
Bentoml bentoml
CPE cpe:2.3:a:bentoml:bentoml:*:*:*:*:*:*:*:*

26 Jan 2026, 23:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-26 23:16

Updated : 2026-06-17 10:22


NVD link : CVE-2026-24123

Mitre link : CVE-2026-24123

CVE.ORG link : CVE-2026-24123


JSON object : View

Products Affected

bentoml

  • bentoml
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')