CVE-2025-32375PoC(bentoml / bentoml)

LOWCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4.8, there was an insecure deserialization in BentoML's runner server. By setting specific headers and parameters in the POST request, it is possible to execute any unauthorized arbitrary code on the server, which will grant the attackers to have the initial access and information disclosure on the server. This vulnerability is fixed in 1.4.8.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-502

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • bentoml

Threat summary

  • Public PoC is present in monitored signal
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 2 signals
  • Technical details provided in 1 signal
  • Exploit: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-04-03); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
bentoml

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-04-03: 1Mentions · 2026-04-04: 1PoC Mentioned / Linked · 2026-04-03: 1PoC Mentioned / Linked · 2026-04-04: 1Technical Details · 2026-04-04: 104-0304-04
Signal classification2 categories
PoC
150.0%
Exploit
150.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-031
PoC1
2026-04-041
Exploit1
Full discourse2 posts
  • Secwiser - Cyber Security Insights@Secwiserapp
    Exploit

    BentoML Remote Code Execution via Unsafe Pickle Summary: CVE-2025-32375 enables unauthenticated RCE in BentoML runner server via insecure pickle.loads() of crafted HTTP payloads. No auth, root-level execution, full host compromise. Lessons: avoid pickle on untrusted data; never expose ML services to untrusted networks; run with least privilege. Read more: https://medium.com/@cyber_public_school/cve-2025-32375-walkthrough-proving-ground-oscp-efd60fd695cd?source=rss------cybersecurity-5 Discover the app: https://www.secwiser.com/app #CyberSecurity #AppSec #Vulnerability #RCE #AIsecurity #MachineLearning #ArtificialIntelligence #CVE202532375 #Secwiser #CyberTech #MLSecurity #DevSecOps

    Post summary

    The post outlines CVE-2025-32375, explaining how an insecure pickle.loads() in BentoML exposes a root-level RCE, and references a Medium walkthrough while omitting patch or active abuse details.

    00000250
    19 followersView on X
  • ‘BBWriteups’@bbwriteup
    PoC

    "CVE-2025–32375 Walkthrough (Proving Ground-OSCP)" by Cyber Public School #BugBounty #Cybersecurity #Hacking #InfoSec https://medium.com/@cyber_public_school/cve-2025-32375-walkthrough-proving-ground-oscp-efd60fd695cd

    Post summary

    The Medium article appears to be a walkthrough for CVE-2025‑32375, focusing on demonstrating a Proof of Concept rather than providing exploit code or reporting active attacks, with no patch or detailed technical information mentioned.

    00000284
    559 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appbentomlbentoml---

Explore more