Database/Container, Kubernetes & orchestration
BentoML (Dockerfile template, docker.base_image interpolation): A multi-line docker.base_image value in bento.yaml
Impact
A multi-line docker.base_image value in bento.yaml smuggles arbitrary directives into the generated Dockerfile, and bentoml containerize then executes them via docker build on the machine doing the build. On a shared build node or CI runner that is code execution with the builder's credentials - registry push tokens, cloud roles, and whatever else the runner holds.
Who can reach it
Anyone who can get a victim to run bentoml containerize against an attacker-supplied bento.yaml - a pull request, a shared model repo, or a marketplace bento.
What to do
Upgrade BentoML to 1.4.39 or later. Run bentoml build and containerize for untrusted bentos in a throwaway sandbox with no registry or cloud credentials mounted, since this is one of a series of Dockerfile-template injection bugs in the same code path.
References
Related entries
- Rancher: plaintext non-expiring registration tokens let an attacker join a rogue node to a clusterCVE-2026-55997 · Rancher (downstream cluster registration tokens)High
- Portainer CE: non-canonical URL path defeats Docker proxy authorization, granting root on the Docker hostCVE-2026-72533 · Portainer CE (Docker API proxy authorization middleware)High
- Dokploy: WebSocket handlers skip per-server authorization, giving any org member root terminalsCVE-2026-72883 · Dokploy (WebSocket terminal, container-terminal, logs and stats handlers)High
- OpenChoreo: workflow parameters interpolated into sh -c run as commands in privileged build podsCVE-2026-73667 · OpenChoreo Workflow Plane (sample workflow templates, sh -c parameter interpolation)High
- OpenChoreo API: project-scoped users can exec into and read wirelogs of other projects' componentsCVE-2026-73841 · OpenChoreo openchoreo-api (component exec and wirelogs handlers)High
- KubeEdge CloudCore: unauthenticated node task status reports let anyone falsify node upgrade resultsCVE-2026-82473 · KubeEdge CloudCore (CloudHub HTTPS server, node task status endpoints)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.