Executive brief
BentoML is a platform for building and deploying machine learning models. A security flaw allows an attacker to create a malicious model archive that, when imported and processed by a user, executes arbitrary code on the user's computer. This could lead to full system takeover, theft of sensitive data like API keys or source code, and unauthorized access to cloud environments.
Technical details
The vulnerability is a Server-Side Template Injection (SSTI) in the `generate_containerfile()` function within `src/bentoml/_internal/container/generate.py`. It stems from the use of an unsandboxed `jinja2.Environment` configured with the dangerous `jinja2.ext.do` and `jinja2.ext.debug` extensions. An attacker can craft a malicious `dockerfile_template` inside a bento archive; when a victim runs `bentoml containerize` on this archive, the template is rendered on the host machine. Because the rendering occurs before Docker isolation is established, the attacker achieves arbitrary Python execution directly on the host OS. The issue is fixed in version 1.4.38 by migrating to `jinja2.sandbox.SandboxedEnvironment`.
Affected products
- BentoML BentoML <= 1.4.37
Timeline
- 2026-04-02: disclosed
- 2026-04-03: advisory
- 2026-04-03: patched: Fixed in version 1.4.38