Database/AI/ML frameworks & serving
BentoML (`docker.system_packages`): Command injection through the package list field
CVE-2026-33744AI/ML frameworks & servingcurated
Impact
Command injection through the package list field
Who can reach it
Customer-supplied build config
What to do
Upgrade to 1.4.37+
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.