By vendor

Bentoml vulnerabilities

Known CVEs affecting Bentoml products, prioritized by severity, with SEC.co remediation and detection guidance.

1 published vulnerability

  • CVE-2026-15035MEDIUM 5.3

    A command injection vulnerability exists in bentoml OpenLLM 0.6.30 where attackers with local access can manipulate the `cmd` argument passed to the `async_run_command` function, allowing them to execute arbitrary system commands. The vulnerability requires local system access and valid credentials, limiting its immediate threat scope but posing risk to multi-tenant or shared development environments. Public exploit information is available.