
BentoML Remote Code Execution via Unsafe Pickle Summary: CVE-2025-32375 enables unauthenticated RCE in BentoML runner server via insecure pickle.loads() of crafted HTTP payloads. No auth, root-level execution, full host compromise. Lessons: avoid pickle on untrusted data; never expose ML services to untrusted networks; run with least privilege. Read more: https://medium.com/@cyber_public_school/cve-2025-32375-walkthrough-proving-ground-oscp-efd60fd695cd?source=rss------cybersecurity-5 Discover the app: https://www.secwiser.com/app #CyberSecurity #AppSec #Vulnerability #RCE #AIsecurity #MachineLearning #ArtificialIntelligence #CVE202532375 #Secwiser #CyberTech #MLSecurity #DevSecOps
Post summary
The post outlines CVE-2025-32375, explaining how an insecure pickle.loads() in BentoML exposes a root-level RCE, and references a Medium walkthrough while omitting patch or active abuse details.

