bentoml
Security Risk Profile
Security Risk Score
Comprehensive risk assessment based on 16 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from March 20, 2025 to present
Threat Assessment
Severity Distribution
Exploit Likelihood
Age Distribution
Common Weaknesses (CWE)
Most Affected Products
Recent Vulnerabilities
See more →bentoml OpenLLM Model Repository Directory Name common.py async_run_command command injection
BentoML: Dockerfile command injection via envs[*].name in bentofile.yaml
BentoML: Dockerfile command injection via docker.base_image
BentoML has Information Disclosure in `bentoml build` via symlink traversal in the build context
BentoML has a Server-Side Template Injection via unsandboxed Jinja2 Environment in Dockerfile generation
BentoML: command injection in cloud deployment setup script (deployment.py)
BentoML has Dockerfile Command Injection via system_packages in bentofile.yaml
BentoML has an Arbitrary File Write via Symlink Path Traversal in Tar Extraction
BentoML has a Path Traversal via Bentofile Configuration
BentoML is Vulnerable to an SSRF Attack Through File Upload Processing
Monitor bentoml in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.