Junglewise Threat Intelligence

CVE-2026-44346: BentoML command injection in Dockerfile generation via bentofile.yaml

CVE-2026-44346 · Severity: high · CVSS 8.8 · Published 2026-05-27

Technologies: bentoml (PyPI). Vendors: PyPI.

Executive brief

BentoML is a platform for building and deploying machine learning models. A vulnerability exists where a specially crafted configuration file can inject malicious commands into the container build process. If a user imports a malicious model and attempts to containerize it, an attacker could execute arbitrary code on the user's build machine, potentially leading to data theft or full system compromise.

Technical details

A command injection vulnerability exists in BentoML's Dockerfile generation logic. The `envs[*].name` field in `bentofile.yaml` is interpolated raw into Jinja2 templates (specifically `base_v2.j2`) without proper escaping or newline filtering. An attacker can craft a `bentofile.yaml` with newline-injected values in the environment variable names to insert arbitrary `RUN` directives into the resulting Dockerfile. When a victim runs `bentoml containerize` on a malicious bento, these injected commands execute on the host during the `docker build` phase. This is a sibling vulnerability to CVE-2026-33744 and CVE-2026-35043, which addressed similar issues in other fields. The issue is fixed in version 1.4.39.

Affected products

  • BentoML bentoml <= 1.4.38

Timeline

  • 2026-05-11: advisory: GitHub Advisory GHSA-w2pm-x38x-jp44 published
  • 2026-05-27: disclosed: NVD publication of CVE-2026-44346
  • 2026-05-07: patched: Version 1.4.39 released

References

Related threats