Database/AI/ML frameworks & serving
BentoML (file upload): SSRF in the file-upload path
CVSS 9.9CVE-2025-54381AI/ML frameworks & servingcurated
Impact
SSRF in the file-upload path
Who can reach it
Authenticated or unauthenticated request depending on deployment
What to do
Upgrade to 1.4.19+
References
Related entries
- OpenShift AI MaaS API: any in-cluster pod forges identity headers to impersonate tenantsCVE-2026-14450 · Red Hat OpenShift AI MaaS API (Kuadrant AuthPolicy gateway)Critical
- NVIDIA OpenShell: incomplete input denylist in the sandbox provisioning API allows code executionCVE-2026-65083 · NVIDIA OpenShell (sandbox provisioning API)Critical
- NVIDIA OpenShell: sandbox escape lets confined code run outside the sandboxCVE-2026-65093 · NVIDIA OpenShell (agent sandbox confinement)Critical
- MCPHub: any authenticated user can register an MCP server and run arbitrary commands as the service userCVE-2026-79748 · MCPHub (POST /api/servers, PUT /api/servers/:name)Critical
- GitLab AI Gateway: crafted Duo flow config escapes the prompt template sandbox into command executionCVE-2026-90970 · GitLab AI Gateway (Duo Agent Platform flow configuration)Critical
- scikit-learn / joblib: `joblib.load()` executes commands from an untrusted file via `__reduce__`CVE-2020-13092 · scikit-learn / joblibCritical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.