Database/AI/ML frameworks & serving
BentoML (runner server): Deserialization RCE on the internal runner server
CVSS 9.8CVE-2024-9070AI/ML frameworks & servingcurated
Impact
Deserialization RCE on the internal runner server
Who can reach it
Network to the runner port — reachable by a co-tenant in a flat cluster network
What to do
Upgrade past 1.3.4.post1; runner ports must be namespace-local
References
Related entries
- MLflow (auth): Weak password requirementsCVE-2025-11200 · MLflow (auth)Critical
- MLflow (model creation): Directory traversal on model creationCVE-2025-11201 · MLflow (model creation)Critical
- MLflow (serving container init): Command injection in `_install_model_dependencies`CVE-2025-15379 · MLflow (serving container init)Critical
- Keras (`Model.load_model`): Arbitrary code execution from a crafted `.keras` archive even with `safe_mode=True`CVE-2025-1550 · Keras (`Model.load_model`)Critical
- LlamaIndex (vector store integrations): SQL injection across multiple vector store integrationsCVE-2025-1793 · LlamaIndex (vector store integrations)Critical
- picklescan (model scanner): Scanner fails to detect malicious pickles when ZIP flag bits are flippedCVE-2025-1945 · picklescan (model scanner)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.