Database/AI/ML frameworks & serving
BentoML (bentoml build, symlink dereferencing in the build context): bentoml build follows symlinks inside the build
Impact
bentoml build follows symlinks inside the build context and copies the target's contents into the bento. A symlink planted in an untrusted repository pulls whatever the builder can read - config files, tokens, key material - into the packaged artifact without the builder noticing.
Who can reach it
A victim who runs bentoml build against an attacker-supplied repository or build context. Local to the build machine.
What to do
Upgrade BentoML to 1.4.39 or later. Until then, build only in a container whose filesystem contains nothing you would not ship, and inspect the file list of bentos built from third-party sources before distributing them.
References
Related entries
- NVIDIA NemoClaw: sensitive information visible in process invocation leads to information disclosureCVE-2026-65088 · NVIDIA NemoClaw (process invocation exposing sensitive information)Medium
- Kubeflow (Pipelines UI): Stored XSS in the pipeline viewCVE-2024-9526 · Kubeflow (Pipelines UI)Medium
- JupyterLab: extension-manager uninstall passes option-like names to pip, allowing file read and internal SSRFCVE-2026-102904 · JupyterLab PyPI Extension Manager (uninstall handler argument injection)Medium
- Intel oneCCL Bindings for PyTorch: protection mechanism failure allows local privilege escalationCVE-2026-24693 · Intel oneCCL Bindings for PyTorch (protection mechanism failure)Medium
- TorchServe (model/workflow API): Information disclosure of files on the serving hostCVE-2023-48299 · TorchServe (model/workflow API)Medium
- llama.cpp (RPC backend): Arbitrary address read via `rpc_tensor.data`CVE-2024-42478 · llama.cpp (RPC backend)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.