CVE Explorer
CVE-2026-40610
BentoML is a Python library for building online serving systems optimized for AI apps and model inference. In versions 1.4.38 and prior, the build packaging workflow follows attacker-controlled symlinks inside the build context and copies the referenced file contents into the generated Bento artifact. If a victim builds an untrusted repository or other attacker-supplied build context, the attacker can place a symlink such as loot.txt -> /tmp/outside-marker.txt or a link to a more sensitive local
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"BentoML","vendor":"bentoml","versions":[{"status":"affected","version":"< 1.4.39"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:2e1f0f168c2f3823a6bf01d97f7836875be660cbc72990d9241592d959e80697 · sha256:43885ff6fd5b0167… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"LOCAL","availabilityImpact":"NONE","baseScore":5.5,"baseSeverity":"MEDIUM","confidentialityImpact":"HIGH","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:2e1f0f168c2f3823a6bf01d97f7836875be660cbc72990d9241592d959e80697 · sha256:43885ff6fd5b0167… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-59","description":"CWE-59: Improper Link Resolution Before File Access ('Link Following')","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:2e1f0f168c2f3823a6bf01d97f7836875be660cbc72990d9241592d959e80697 · sha256:43885ff6fd5b0167… · /containers/cna/problemTypes/0/descriptions/0
Source references
4 source assertions{"name":"https://github.com/bentoml/BentoML/commit/5fb7cd41f92e2a56b45391284cf15b9ac9963a1f","tags":["x_refsource_MISC"],"url":"https://github.com/bentoml/BentoML/commit/5fb7cd41f92e2a56b45391284cf15b9ac9963a1f"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:2e1f0f168c2f3823a6bf01d97f7836875be660cbc72990d9241592d959e80697 · sha256:43885ff6fd5b0167… · /containers/cna/references/1
{"name":"https://github.com/bentoml/BentoML/releases/tag/v1.4.39","tags":["x_refsource_MISC"],"url":"https://github.com/bentoml/BentoML/releases/tag/v1.4.39"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:2e1f0f168c2f3823a6bf01d97f7836875be660cbc72990d9241592d959e80697 · sha256:43885ff6fd5b0167… · /containers/cna/references/2
{"name":"https://github.com/bentoml/BentoML/security/advisories/GHSA-mcfx-4vc6-qgxv","tags":["x_refsource_CONFIRM"],"url":"https://github.com/bentoml/BentoML/security/advisories/GHSA-mcfx-4vc6-qgxv"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:2e1f0f168c2f3823a6bf01d97f7836875be660cbc72990d9241592d959e80697 · sha256:43885ff6fd5b0167… · /containers/cna/references/0
{"tags":["exploit"],"url":"https://github.com/bentoml/BentoML/security/advisories/GHSA-mcfx-4vc6-qgxv"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:2e1f0f168c2f3823a6bf01d97f7836875be660cbc72990d9241592d959e80697 · sha256:43885ff6fd5b0167… · /containers/adp/0/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.