Executive brief
BentoML is a platform for building and deploying machine learning models. A vulnerability exists where a specially crafted configuration file can inject malicious commands into the container build process. If a user imports a malicious model and attempts to containerize it, an attacker could execute arbitrary code on the user's build machine, potentially leading to data theft or full system compromise.
Technical details
A command injection vulnerability exists in BentoML's Dockerfile generation logic. The `envs[*].name` field in `bentofile.yaml` is interpolated raw into Jinja2 templates (specifically `base_v2.j2`) without proper escaping or newline filtering. An attacker can craft a `bentofile.yaml` with newline-injected values in the environment variable names to insert arbitrary `RUN` directives into the resulting Dockerfile. When a victim runs `bentoml containerize` on a malicious bento, these injected commands execute on the host during the `docker build` phase. This is a sibling vulnerability to CVE-2026-33744 and CVE-2026-35043, which addressed similar issues in other fields. The issue is fixed in version 1.4.39.
Affected products
- BentoML bentoml <= 1.4.38
Timeline
- 2026-05-11: advisory: GitHub Advisory GHSA-w2pm-x38x-jp44 published
- 2026-05-27: disclosed: NVD publication of CVE-2026-44346
- 2026-05-07: patched: Version 1.4.39 released