← Vulnerability feed

Vulnerability record · CVE-2026-40610 · published 22 May 2026

CVE-2026-40610: Bentoml link following vulnerability

Bentoml · Bentoml

BentoML is a Python library for building online serving systems optimized for AI apps and model inference. In versions 1.4.38 and prior, the build packaging workflow follows attacker-controlled symlinks inside the build context and copies the referenced file contents into the generated Bento artifact. If a victim builds an untrusted repository or other attacker-supplied build context, the attacker can place a symlink such as loot.txt -> /tmp/outside-marker.txt or a link to a more sensitive local file. When bentoml build runs, BentoML dereferences the symlink and packages the target file contents into the Bento. The leaked file can then propagate further through export, push, or containerization workflows. An attacker can exfiltrate local files from the build host into the Bento artifact, exposing secrets such as cloud credentials, SSH keys, API tokens, environment files, or other sensitive local configurations. Because Bento artifacts are commonly exported, uploaded, stored, or containerized after build, the leaked file contents can spread beyond the original build machine. This issue has been fixed in version 1.4.39.

5.5 CVSS 3.1 Medium EPSS 0.20% · top 90.9% CWE-59 · Link following
5.5CVSS 3.1 base score
0.20%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 2 tagged exploit
6 Oct 2026Last modified by NVD

Description

BentoML is a Python library for building online serving systems optimized for AI apps and model inference. In versions 1.4.38 and prior, the build packaging workflow follows attacker-controlled symlinks inside the build context and copies the referenced file contents into the generated Bento artifact. If a victim builds an untrusted repository or other attacker-supplied build context, the attacker can place a symlink such as loot.txt -> /tmp/outside-marker.txt or a link to a more sensitive local file. When bentoml build runs, BentoML dereferences the symlink and packages the target file contents into the Bento. The leaked file can then propagate further through export, push, or containerization workflows. An attacker can exfiltrate local files from the build host into the Bento artifact, exposing secrets such as cloud credentials, SSH keys, API tokens, environment files, or other sensitive local configurations. Because Bento artifacts are commonly exported, uploaded, stored, or containerized after build, the leaked file contents can spread beyond the original build machine. This issue has been fixed in version 1.4.39.

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-40610 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.9CVE-2025-54381Bentoml server-side request forgery (ssrf) vulnerabilityBentoML is a Python library for building online serving systems optimized for AI apps and model inference. In versions 1.4.0 until 1.4.19, the file u…EPSS 16%9.8CVE-2025-32375BentoML runner server insecure deserialization enables unauthenticated RCEBentoML before 1.4.8 deserializes untrusted data in its runner server. By sending a crafted POST request with specific headers and parameters, an att…EPSS 52%analysed9.8CVE-2025-27520Bentoml deserialization of untrusted data vulnerabilityBentoML is a Python library for building online serving systems optimized for AI apps and model inference. A Remote Code Execution (RCE) vulnerabilit…EPSS 41%9.6CVE-2026-35044Bentoml vulnerabilityBentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4.38, the Dockerfile generation…EPSS 0.48%8.8CVE-2026-44345Bentoml os command injection vulnerabilityBentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4.39, src/bentoml/_internal/con…EPSS 0.48%8.8CVE-2026-44346Bentoml os command injection vulnerabilityBentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4.39, a malicious bentofile.yam…EPSS 0.48%8.6CVE-2026-27905Bentoml link following vulnerabilityBentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4.36, the safe_extract_tarfile(…EPSS 0.22%7.8CVE-2026-35043Bentoml os command injection vulnerabilityBentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4.38, the cloud deployment path…EPSS 0.26%

Source: NIST National Vulnerability Database (record CVE-2026-40610), CISA KEV, FIRST EPSS (scores of 2026-10-10). This page is refreshed as NVD updates the record.