Database/AI/ML frameworks & serving
BentoML 1.3.9 (open redirect in the serving UI): A crafted URL against the BentoML server bounces the visitor to an
Impact
A crafted URL against the BentoML server bounces the visitor to an attacker-chosen site while the link still looks like it points at your model endpoint. Useful for credential phishing against the people who operate or consume the endpoint. No CVE was assigned to the BentoML advisory; the underlying Gradio issue is CVE-2024-4940.
Who can reach it
A remote unauthenticated attacker who gets a user to click a link pointing at the BentoML host.
What to do
Upgrade BentoML past 1.3.9 and restart the serving pods. If you cannot upgrade, block off-host redirect targets at the ingress in front of the endpoint.
References
Related entries
- ClearML: Passwords stored in plaintext in MongoDBCVE-2024-24595 · ClearMLMedium
- JupyterLab: authenticated users bypass administrator plugin lock rules via /lab/api/pluginsCVE-2026-73627 · JupyterLab Extension/Plugin Manager (/lab/api/plugins lock-rule enforcement)Medium
- Ray (dashboard DELETE endpoints): Browser-origin protection covers POST/PUT but not DELETECVE-2026-27482 · Ray (dashboard DELETE endpoints)Medium
- LocalAI (`/models/apply`): SSRF and partial local file inclusionCVE-2024-6095 · LocalAI (`/models/apply`)Medium
- NVIDIA NemoClaw: insufficiently protected credentials allow information disclosure and data tamperingCVE-2026-65087 · NVIDIA NemoClaw (credential storage)Medium
- Linux perf/x86/amd/uncore - memory leak in the events array: Per-CPU northbridge and last-level-cache uncore contextsCVE-2022-49784 · Linux perf/x86/amd/uncore - memory leak in the events arrayMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.