Database/Container, Kubernetes & orchestration
BentoML (bentofile.yaml path fields: description, docker.setup_script, docker.dockerfile_template
Impact
Several bentofile path fields accept traversal, so building an attacker's bento copies arbitrary files from the builder's filesystem into the bento archive. SSH keys, cloud credential files and environment secrets ride along into an artifact that is then pushed to a registry the attacker can read - a clean supply-chain exfiltration path off a shared build host.
Who can reach it
Anyone who can get a victim to run bentoml build on their bentofile. The exfiltration completes when the resulting bento is pushed or shared.
What to do
Upgrade BentoML to 1.4.34 or later. Build untrusted bentos in an isolated container with no credential files present, and scan any bento built from an outside source before pushing it to a shared registry.
References
Related entries
- BentoML: Insecure deserializationCVE-2024-2912 · BentoMLCritical
- BentoML: RCE via insecure deserializationCVE-2025-27520 · BentoMLCritical
- BentoML: Insecure deserialization RCE prior to 1.4.8CVE-2025-32375 · BentoMLCritical
- OpenShift Console: tenant-planted Helm repository makes the console pod fetch arbitrary URLs server-sideCVE-2026-50237 · Red Hat OpenShift Console (Helm catalog proxy, ProjectHelmChartRepository)High
- Envoy Gateway: unauthenticated xDS on port 18000 hands out TLS private keys and full routing configCVE-2026-53714 · Envoy Gateway xDS gRPC server in GatewayNamespaceMode (port 18000)High
- Istio: Authentication Policy exact-path matching allows unauthorized access to HTTP pathsCVE-2020-8595 · IstioHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.