Database/AI/ML frameworks & serving
BentoML (`docker.system_packages`): Command injection through the package list field
CVSS 7.8CVE-2026-33744AI/ML frameworks & servingcurated
Impact
Command injection through the package list field
Who can reach it
Customer-supplied build config
What to do
Upgrade to 1.4.37+
References
Related entries
- BentoML (cloud deployment path, setup.sh generation in deployment.py): The March fix that added shlex.quote to theCVE-2026-35043 · BentoML (cloud deployment path, setup.sh generation in deployment.py)High
- SGLang (`replay_request_dump.py`): Insecure `pickle.load()` on a `.pkl` dumpCVE-2026-3989 · SGLang (`replay_request_dump.py`)High
- llama.cpp (`llama_batch_init`): Integer overflow from unchecked multiplicationCVE-2026-43627 · llama.cpp (`llama_batch_init`)High
- HuggingFace transformers: Critical RCE in all versions before 5.3.0CVE-2026-4372 · HuggingFace transformersHigh
- stable-diffusion.cpp: Memory-safety flaw in model loadingCVE-2026-47749 · stable-diffusion.cppHigh
- PyTorch Lightning (`_load_state`): RCE by importing and executing classes named in the checkpointCVE-2026-58659 · PyTorch Lightning (`_load_state`)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.