bentoml
Security Risk Profile
Security Risk Score
Comprehensive risk assessment based on 17 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from March 20, 2025 to present
Threat Assessment
Severity Distribution
Exploit Likelihood
Age Distribution
Common Weaknesses (CWE)
Most Affected Products
Recent Vulnerabilities
See more →BentoML 1.4.19 through 1.4.39 Server-Side Request Forgery via Unfiltered RFC 6598 Shared Address Space
bentoml OpenLLM Model Repository Directory Name common.py async_run_command command injection
BentoML: Dockerfile command injection via envs[*].name in bentofile.yaml
BentoML: Dockerfile command injection via docker.base_image
BentoML has Information Disclosure in `bentoml build` via symlink traversal in the build context
BentoML has a Server-Side Template Injection via unsandboxed Jinja2 Environment in Dockerfile generation
BentoML: command injection in cloud deployment setup script (deployment.py)
BentoML has Dockerfile Command Injection via system_packages in bentofile.yaml
BentoML has an Arbitrary File Write via Symlink Path Traversal in Tar Extraction
BentoML has a Path Traversal via Bentofile Configuration
Monitor bentoml in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.