CVE-2026-35044General(bentoml / bentoml)

LOWCVSS 9.6 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch bentoml bentoml systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4.38, the Dockerfile generation function generate_containerfile() in src/bentoml/_internal/container/generate.py uses an unsandboxed jinja2.Environment with the jinja2.ext.do extension to render user-provided dockerfile_template files. When a victim imports a malicious bento archive and runs bentoml containerize, attacker-controlled Jinja2 template code executes arbitrary Python directly on the host machine, bypassing all container isolation. This vulnerability is fixed in 1.4.38.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-1336

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • bentoml

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • General: 1 classified signal
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
bentoml

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-04-06: 2Patch / Workaround · 2026-04-06: 1Technical Details · 2026-04-06: 104-06
Signal classification2 categories
General
150.0%
Patch
150.0%
Referenced assets2 URLs
Full discourse2 posts
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-35044: HIGH] Prior to BentoML version 1.4.38, a vulnerability allowed attackers to execute arbitrary Python code on the host machine via unsandboxed Jinja2 templates. Update to the latest version f...#cve,CVE-2026-35044,#cybersecurity https://cvefind.com/CVE-2026-35044

    Post summary

    The tweet announces a high‑severity vulnerability in BentoML that allows code execution via unsandboxed Jinja2 templates and urges users to update to the latest version for protection.

    0000031
    619 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-35044 BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4.38, the Dockerfile generation function generat… https://www.cve.org/CVERecord?id=CVE-2026-35044

    Post summary

    The post merely references the CVE record for BentoML without providing any PoC, exploit details, patch information, or technical specifics.

    0000095
    57.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appbentomlbentoml---

Explore more