<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Thu, 08 Oct 2026 00:26:44 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-274294</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-274294</link>
      <description>EUVD-2026-274294</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-274294</guid>
    </item>
    <item>
      <title>fkie_cve-2026-27905</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-27905</link>
      <description>&lt;p&gt;BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4.36, the safe_extract_tarfile() function validates that each tar member&amp;#39;s path is within the destination directory, but for symlink members it only validates the symlink&amp;#39;s own path, not the symlink&amp;#39;s target. An attacker can create a malicious bento/model tar file containing a symlink pointing outside the extraction directory, followed by a regular file that writes through the symlink, achieving arbitrary file write on the host filesystem. This vulnerability is fixed in 1.4.36.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4.36, the safe_extract_tarfile() function validates that each tar member&amp;#39;s path is within the destination directory, but for symlink members it only validates the symlink&amp;#39;s own path, not the symlink&amp;#39;s target. An attacker can create a malicious bento/model tar file containing a symlink pointing outside the extraction directory, followed by a regular file that writes through the symlink, achieving arbitrary file write on the host filesystem. This vulnerability is fixed in 1.4.36.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-27905</guid>
    </item>
    <item>
      <title>GHSA-m6w7-qv66-g3mf — BentoML Vulnerable to Arbitrary File Write via Symlink Path Traversal in Tar Extraction</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-m6w7-qv66-g3mf</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: bentoml&lt;/p&gt;
&lt;p&gt;# Arbitrary File Write via Symlink Path Traversal in Tar Extraction&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The `safe_extract_tarfile()` function validates that each tar member&amp;#39;s path is within the destination directory, but for symlink members it only validates the symlink&amp;#39;s own path, **not the symlink&amp;#39;s target**. An attacker can create a malicious bento/model tar file containing a symlink pointing outside the extraction directory, followed by a regular file that writes through the symlink, achieving arbitrary file write on the host filesystem.&lt;/p&gt;
&lt;p&gt;## Affected Component&lt;/p&gt;
&lt;p&gt;- **File**: `src/bentoml/_internal/utils/filesystem.py:58-96`
- **Callers**: `src/bentoml/_internal/cloud/bento.py:542`, `src/bentoml/_internal/cloud/model.py:504`
- **Affected versions**: All versions with `safe_extract_tarfile()`&lt;/p&gt;
&lt;p&gt;## Severity&lt;/p&gt;
&lt;p&gt;**CVSS 3.1: 8.1 (High)**
`AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H`&lt;/p&gt;
&lt;p&gt;## Vulnerability Details&lt;/p&gt;
&lt;p&gt;### Vulnerable Code (filesystem.py:58-96)&lt;/p&gt;
&lt;p&gt;```python
def safe_extract_tarfile(tar, destination):
    os.makedirs(destination, exist_ok=True)
    for member in tar.getmembers():
        fn = member.name
        path = os.path.abspath(os.path.join(destination, fn))
        if not Path(path).is_relative_to(destination):  # Line 64: INCOMPLETE
            continue  # Only checks member path, NOT symlink target
        if member.issym():
            tar._extract_member(member, path)  # Line 75: Creates symlink with UNVALIDATED target
        else:
            fp = tar.extractfile(member)
            with open(pa…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: bentoml&lt;/p&gt;
&lt;p&gt;# Arbitrary File Write via Symlink Path Traversal in Tar Extraction&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The `safe_extract_tarfile()` function validates that each tar member&amp;#39;s path is within the destination directory, but for symlink members it only validates the symlink&amp;#39;s own path, **not the symlink&amp;#39;s target**. An attacker can create a malicious bento/model tar file containing a symlink pointing outside the extraction directory, followed by a regular file that writes through the symlink, achieving arbitrary file write on the host filesystem.&lt;/p&gt;
&lt;p&gt;## Affected Component&lt;/p&gt;
&lt;p&gt;- **File**: `src/bentoml/_internal/utils/filesystem.py:58-96`
- **Callers**: `src/bentoml/_internal/cloud/bento.py:542`, `src/bentoml/_internal/cloud/model.py:504`
- **Affected versions**: All versions with `safe_extract_tarfile()`&lt;/p&gt;
&lt;p&gt;## Severity&lt;/p&gt;
&lt;p&gt;**CVSS 3.1: 8.1 (High)**
`AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H`&lt;/p&gt;
&lt;p&gt;## Vulnerability Details&lt;/p&gt;
&lt;p&gt;### Vulnerable Code (filesystem.py:58-96)&lt;/p&gt;
&lt;p&gt;```python
def safe_extract_tarfile(tar, destination):
    os.makedirs(destination, exist_ok=True)
    for member in tar.getmembers():
        fn = member.name
        path = os.path.abspath(os.path.join(destination, fn))
        if not Path(path).is_relative_to(destination):  # Line 64: INCOMPLETE
            continue  # Only checks member path, NOT symlink target
        if member.issym():
            tar._extract_member(member, path)  # Line 75: Creates symlink with UNVALIDATED target
        else:
            fp = tar.extractfile(member)
            with open(pa…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-m6w7-qv66-g3mf</guid>
    </item>
    <item>
      <title>PYSEC-2026-2398 — BentoML Vulnerable to Arbitrary File Write via Symlink Path Traversal in Tar Extraction</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2026-2398</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: bentoml&lt;/p&gt;
&lt;p&gt;# Arbitrary File Write via Symlink Path Traversal in Tar Extraction&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The `safe_extract_tarfile()` function validates that each tar member&amp;#39;s path is within the destination directory, but for symlink members it only validates the symlink&amp;#39;s own path, **not the symlink&amp;#39;s target**. An attacker can create a malicious bento/model tar file containing a symlink pointing outside the extraction directory, followed by a regular file that writes through the symlink, achieving arbitrary file write on the host filesystem.&lt;/p&gt;
&lt;p&gt;## Affected Component&lt;/p&gt;
&lt;p&gt;- **File**: `src/bentoml/_internal/utils/filesystem.py:58-96`
- **Callers**: `src/bentoml/_internal/cloud/bento.py:542`, `src/bentoml/_internal/cloud/model.py:504`
- **Affected versions**: All versions with `safe_extract_tarfile()`&lt;/p&gt;
&lt;p&gt;## Severity&lt;/p&gt;
&lt;p&gt;**CVSS 3.1: 8.1 (High)**
`AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H`&lt;/p&gt;
&lt;p&gt;## Vulnerability Details&lt;/p&gt;
&lt;p&gt;### Vulnerable Code (filesystem.py:58-96)&lt;/p&gt;
&lt;p&gt;```python
def safe_extract_tarfile(tar, destination):
    os.makedirs(destination, exist_ok=True)
    for member in tar.getmembers():
        fn = member.name
        path = os.path.abspath(os.path.join(destination, fn))
        if not Path(path).is_relative_to(destination):  # Line 64: INCOMPLETE
            continue  # Only checks member path, NOT symlink target
        if member.issym():
            tar._extract_member(member, path)  # Line 75: Creates symlink with UNVALIDATED target
        else:
            fp = tar.extractfile(member)
            with open(pa…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: bentoml&lt;/p&gt;
&lt;p&gt;# Arbitrary File Write via Symlink Path Traversal in Tar Extraction&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The `safe_extract_tarfile()` function validates that each tar member&amp;#39;s path is within the destination directory, but for symlink members it only validates the symlink&amp;#39;s own path, **not the symlink&amp;#39;s target**. An attacker can create a malicious bento/model tar file containing a symlink pointing outside the extraction directory, followed by a regular file that writes through the symlink, achieving arbitrary file write on the host filesystem.&lt;/p&gt;
&lt;p&gt;## Affected Component&lt;/p&gt;
&lt;p&gt;- **File**: `src/bentoml/_internal/utils/filesystem.py:58-96`
- **Callers**: `src/bentoml/_internal/cloud/bento.py:542`, `src/bentoml/_internal/cloud/model.py:504`
- **Affected versions**: All versions with `safe_extract_tarfile()`&lt;/p&gt;
&lt;p&gt;## Severity&lt;/p&gt;
&lt;p&gt;**CVSS 3.1: 8.1 (High)**
`AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H`&lt;/p&gt;
&lt;p&gt;## Vulnerability Details&lt;/p&gt;
&lt;p&gt;### Vulnerable Code (filesystem.py:58-96)&lt;/p&gt;
&lt;p&gt;```python
def safe_extract_tarfile(tar, destination):
    os.makedirs(destination, exist_ok=True)
    for member in tar.getmembers():
        fn = member.name
        path = os.path.abspath(os.path.join(destination, fn))
        if not Path(path).is_relative_to(destination):  # Line 64: INCOMPLETE
            continue  # Only checks member path, NOT symlink target
        if member.issym():
            tar._extract_member(member, path)  # Line 75: Creates symlink with UNVALIDATED target
        else:
            fp = tar.extractfile(member)
            with open(pa…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2026-2398</guid>
    </item>
  </channel>
</rss>
