<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-08T04:44:16.300025+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-33744</id>
    <title>CVE-2026-33744 — BentoML has Dockerfile Command Injection via system_packages in bentofile.yaml</title>
    <updated>2026-10-08T04:44:16.301885+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> BentoML</p>
<p>BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4.37, the `docker.system_packages` field in `bentofile.yaml` accepts arbitrary strings that are interpolated directly into Dockerfile `RUN` commands without sanitization. Since `system_packages` is semantically a list of OS package names (data), users do not expect values to be interpreted as shell commands. A malicious `bentofile.yaml` achieves arbitrary command execution during `bentoml containerize` / `docker build`. Version 1.4.37 fixes the issue.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-33744"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-jfjg-vc52-wqvf</id>
    <title>GHSA-jfjg-vc52-wqvf — BentoML has Dockerfile Command Injection via system_packages in bentofile.yaml</title>
    <updated>2026-10-08T04:44:16.301971+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: bentoml</p>
<p>## Summary</p>
<p>The `docker.system_packages` field in `bentofile.yaml` accepts arbitrary strings that are interpolated directly into Dockerfile `RUN` commands without sanitization. Since `system_packages` is semantically a list of OS package names (data), users do not expect values to be interpreted as shell commands. A malicious `bentofile.yaml` achieves arbitrary command execution during `bentoml containerize` / `docker build`.</p>
<p>## Affected Component</p>
<p>- `src/_bentoml_sdk/images.py:85-89` — `.format(packages=" ".join(packages))` into shell command
- `src/bentoml/_internal/container/frontend/dockerfile/templates/base_debian.j2:13` — `{{ __options__system_packages | join(' ') }}`
- `src/bentoml/_internal/bento/build_config.py:174` — No validation on `system_packages`
- All distro install commands in `src/bentoml/_internal/container/frontend/dockerfile/__init__.py`</p>
<p>## Affected Versions</p>
<p>All versions supporting `docker.system_packages` in `bentofile.yaml`, confirmed on 1.4.36.</p>
<p>## Steps to Reproduce</p>
<p>1. Create a project directory with:</p>
<p>**service.py:**
```python
import bentoml</p>
<p>@bentoml.service
class MyService:
    @bentoml.api
    def predict(self) -&gt; str:
        return "hello"
```</p>
<p>**bentofile.yaml:**
```yaml
service: "service:MyService"
docker:
  system_packages:
    - "curl &amp;&amp; id &gt; /tmp/bentoml-pwned #"
```</p>
<p>2. Run:
```bash
bentoml build
```</p>
<p>3. Examine the generated Dockerfile at `~/bentoml/bentos/my_service/&lt;tag&gt;/env/docker/Dockerfile`. Line 41 will contain:
```dockerfile
R…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-jfjg-vc52-wqvf"/>
  </entry>
</feed>
