Ad

CVE-2026-27905

HIGH CVSS 4.0: 8.6 EPSS 0.01%
Updated Mar 04, 2026
Python
Parameter Value
CVSS 8.6 (HIGH)
Fixed In 1.4.36
Type CWE-59 (Improper Link Resolution (Неправильное разрешение ссылок))
Vendor Python
Public PoC No

BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4.36, the safe_extract_tarfile() function validates that each tar member's path is within the destination directory, but for symlink members it only validates the symlink's own path, not the symlink's target. An attacker can create a malicious bento/model tar file containing a symlink pointing outside the extraction directory, followed by a regular file that writes through the symlink, achieving arbitrary file write on the host filesystem.

This vulnerability is fixed in 1.4.36.

Attack Parameters

Attack Vector
Local
Нужен локальный доступ
Attack Complexity
Low
Легко эксплуатировать
Attack Requirements
None
Нет дополнительных условий
Privileges Required
None
Права не нужны
User Interaction
None
Не нужно действие пользователя

Impact Assessment

Confidentiality
High
Полная утечка данных
Integrity
High
Полная модификация данных
Availability
High
Полный отказ в обслуживании

CVSS Vector v4.0