<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-07T23:34:41.530426+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-274294</id>
    <title>EUVD-2026-274294</title>
    <updated>2026-10-07T23:34:41.534183+00:00</updated>
    <content>EUVD-2026-274294</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-274294"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-27905</id>
    <title>fkie_cve-2026-27905</title>
    <updated>2026-10-07T23:34:41.534215+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4.36, the safe_extract_tarfile() function validates that each tar member's path is within the destination directory, but for symlink members it only validates the symlink's own path, not the symlink's target. An attacker can create a malicious bento/model tar file containing a symlink pointing outside the extraction directory, followed by a regular file that writes through the symlink, achieving arbitrary file write on the host filesystem. This vulnerability is fixed in 1.4.36.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-27905"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-m6w7-qv66-g3mf</id>
    <title>GHSA-m6w7-qv66-g3mf — BentoML Vulnerable to Arbitrary File Write via Symlink Path Traversal in Tar Extraction</title>
    <updated>2026-10-07T23:34:41.534249+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: bentoml</p>
<p># Arbitrary File Write via Symlink Path Traversal in Tar Extraction</p>
<p>## Summary</p>
<p>The `safe_extract_tarfile()` function validates that each tar member's path is within the destination directory, but for symlink members it only validates the symlink's own path, **not the symlink's target**. An attacker can create a malicious bento/model tar file containing a symlink pointing outside the extraction directory, followed by a regular file that writes through the symlink, achieving arbitrary file write on the host filesystem.</p>
<p>## Affected Component</p>
<p>- **File**: `src/bentoml/_internal/utils/filesystem.py:58-96`
- **Callers**: `src/bentoml/_internal/cloud/bento.py:542`, `src/bentoml/_internal/cloud/model.py:504`
- **Affected versions**: All versions with `safe_extract_tarfile()`</p>
<p>## Severity</p>
<p>**CVSS 3.1: 8.1 (High)**
`AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H`</p>
<p>## Vulnerability Details</p>
<p>### Vulnerable Code (filesystem.py:58-96)</p>
<p>```python
def safe_extract_tarfile(tar, destination):
    os.makedirs(destination, exist_ok=True)
    for member in tar.getmembers():
        fn = member.name
        path = os.path.abspath(os.path.join(destination, fn))
        if not Path(path).is_relative_to(destination):  # Line 64: INCOMPLETE
            continue  # Only checks member path, NOT symlink target
        if member.issym():
            tar._extract_member(member, path)  # Line 75: Creates symlink with UNVALIDATED target
        else:
            fp = tar.extractfile(member)
            with open(pa…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-m6w7-qv66-g3mf"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2026-2398</id>
    <title>PYSEC-2026-2398 — BentoML Vulnerable to Arbitrary File Write via Symlink Path Traversal in Tar Extraction</title>
    <updated>2026-10-07T23:34:41.534304+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: bentoml</p>
<p># Arbitrary File Write via Symlink Path Traversal in Tar Extraction</p>
<p>## Summary</p>
<p>The `safe_extract_tarfile()` function validates that each tar member's path is within the destination directory, but for symlink members it only validates the symlink's own path, **not the symlink's target**. An attacker can create a malicious bento/model tar file containing a symlink pointing outside the extraction directory, followed by a regular file that writes through the symlink, achieving arbitrary file write on the host filesystem.</p>
<p>## Affected Component</p>
<p>- **File**: `src/bentoml/_internal/utils/filesystem.py:58-96`
- **Callers**: `src/bentoml/_internal/cloud/bento.py:542`, `src/bentoml/_internal/cloud/model.py:504`
- **Affected versions**: All versions with `safe_extract_tarfile()`</p>
<p>## Severity</p>
<p>**CVSS 3.1: 8.1 (High)**
`AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H`</p>
<p>## Vulnerability Details</p>
<p>### Vulnerable Code (filesystem.py:58-96)</p>
<p>```python
def safe_extract_tarfile(tar, destination):
    os.makedirs(destination, exist_ok=True)
    for member in tar.getmembers():
        fn = member.name
        path = os.path.abspath(os.path.join(destination, fn))
        if not Path(path).is_relative_to(destination):  # Line 64: INCOMPLETE
            continue  # Only checks member path, NOT symlink target
        if member.issym():
            tar._extract_member(member, path)  # Line 75: Creates symlink with UNVALIDATED target
        else:
            fp = tar.extractfile(member)
            with open(pa…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2026-2398"/>
  </entry>
</feed>
