<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-08T23:18:39.638504+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-321427</id>
    <title>EUVD-2026-321427</title>
    <updated>2026-10-08T23:18:39.721130+00:00</updated>
    <content>EUVD-2026-321427</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-321427"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-40610</id>
    <title>fkie_cve-2026-40610</title>
    <updated>2026-10-08T23:18:39.721170+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>BentoML is a Python library for building online serving systems optimized for AI apps and model inference. In versions 1.4.38 and prior, the build packaging workflow follows attacker-controlled symlinks inside the build context and copies the referenced file contents into the generated Bento artifact. If a victim builds an untrusted repository or other attacker-supplied build context, the attacker can place a symlink such as loot.txt -&gt; /tmp/outside-marker.txt or a link to a more sensitive local file. When bentoml build runs, BentoML dereferences the symlink and packages the target file contents into the Bento. The leaked file can then propagate further through export, push, or containerization workflows. An attacker can exfiltrate local files from the build host into the Bento artifact, exposing secrets such as cloud credentials, SSH keys, API tokens, environment files, or other sensitive local configurations. Because Bento artifacts are commonly exported, uploaded, stored, or containerized after build, the leaked file contents can spread beyond the original build machine. This issue has been fixed in version 1.4.39.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-40610"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-mcfx-4vc6-qgxv</id>
    <title>GHSA-mcfx-4vc6-qgxv — BentoML has Information Disclosure in `bentoml build` via symlink traversal in the build context</title>
    <updated>2026-10-08T23:18:39.721213+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: bentoml</p>
<p>### Summary
BentoML's `bentoml build` packaging workflow follows attacker-controlled symlinks inside the build context and copies the referenced file contents into the generated Bento artifact.</p>
<p>If a victim builds an untrusted repository or other attacker-supplied build context, the attacker can place a symlink such as `loot.txt -&gt; /tmp/outside-marker.txt` or a link to a more sensitive local file. When `bentoml build` runs, BentoML dereferences the symlink and packages the target file contents into the Bento. The leaked file can then propagate further through export, push, or containerization workflows.</p>
<p>### Details
The vulnerable code walks files under the build context and copies each matched entry into the Bento source directory:</p>
<p>```python
for root, _, files in os.walk(ctx_path):
    for f in files:
        dir_path = os.path.relpath(root, ctx_path)
        path = os.path.join(dir_path, f).replace(os.sep, "/")
        if specs.includes(path):
            src_file = ctx_path.joinpath(path)
            dst_file = target_fs.joinpath(dest_path)
            shutil.copy(src_file, dst_file)
```</p>
<p>There is no validation that the resolved path of `src_file` remains inside `ctx_path` before `shutil.copy` dereferences the source path. As a result, a repository-controlled symlink can cross the trust boundary from `attacker-controlled repository content` to `developer/CI host filesystem` during the build process.</p>
<p>This is a build-time path traversal / symlink traversal issue in the pa…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-mcfx-4vc6-qgxv"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2026-2399</id>
    <title>PYSEC-2026-2399 — BentoML has Information Disclosure in `bentoml build` via symlink traversal in the build context</title>
    <updated>2026-10-08T23:18:39.721268+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: bentoml</p>
<p>### Summary
BentoML's `bentoml build` packaging workflow follows attacker-controlled symlinks inside the build context and copies the referenced file contents into the generated Bento artifact.</p>
<p>If a victim builds an untrusted repository or other attacker-supplied build context, the attacker can place a symlink such as `loot.txt -&gt; /tmp/outside-marker.txt` or a link to a more sensitive local file. When `bentoml build` runs, BentoML dereferences the symlink and packages the target file contents into the Bento. The leaked file can then propagate further through export, push, or containerization workflows.</p>
<p>### Details
The vulnerable code walks files under the build context and copies each matched entry into the Bento source directory:</p>
<p>```python
for root, _, files in os.walk(ctx_path):
    for f in files:
        dir_path = os.path.relpath(root, ctx_path)
        path = os.path.join(dir_path, f).replace(os.sep, "/")
        if specs.includes(path):
            src_file = ctx_path.joinpath(path)
            dst_file = target_fs.joinpath(dest_path)
            shutil.copy(src_file, dst_file)
```</p>
<p>There is no validation that the resolved path of `src_file` remains inside `ctx_path` before `shutil.copy` dereferences the source path. As a result, a repository-controlled symlink can cross the trust boundary from `attacker-controlled repository content` to `developer/CI host filesystem` during the build process.</p>
<p>This is a build-time path traversal / symlink traversal issue in the pa…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2026-2399"/>
  </entry>
</feed>
