<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Thu, 08 Oct 2026 13:55:57 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-280503</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-280503</link>
      <description>EUVD-2026-280503</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-280503</guid>
    </item>
    <item>
      <title>fkie_cve-2026-35044</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-35044</link>
      <description>&lt;p&gt;BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4.38, the Dockerfile generation function generate_containerfile() in src/bentoml/_internal/container/generate.py uses an unsandboxed jinja2.Environment with the jinja2.ext.do extension to render user-provided dockerfile_template files. When a victim imports a malicious bento archive and runs bentoml containerize, attacker-controlled Jinja2 template code executes arbitrary Python directly on the host machine, bypassing all container isolation. This vulnerability is fixed in 1.4.38.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4.38, the Dockerfile generation function generate_containerfile() in src/bentoml/_internal/container/generate.py uses an unsandboxed jinja2.Environment with the jinja2.ext.do extension to render user-provided dockerfile_template files. When a victim imports a malicious bento archive and runs bentoml containerize, attacker-controlled Jinja2 template code executes arbitrary Python directly on the host machine, bypassing all container isolation. This vulnerability is fixed in 1.4.38.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-35044</guid>
    </item>
    <item>
      <title>GHSA-v959-cwq9-7hr6 — BentoML: SSTI via Unsandboxed Jinja2 in Dockerfile Generation</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-v959-cwq9-7hr6</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: bentoml&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The Dockerfile generation function `generate_containerfile()` in `src/bentoml/_internal/container/generate.py` uses an unsandboxed `jinja2.Environment` with the `jinja2.ext.do` extension to render user-provided `dockerfile_template` files. When a victim imports a malicious bento archive and runs `bentoml containerize`, attacker-controlled Jinja2 template code executes arbitrary Python directly on the host machine, bypassing all container isolation.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;The vulnerability exists in the `generate_containerfile()` function at `src/bentoml/_internal/container/generate.py:155-157`:&lt;/p&gt;
&lt;p&gt;```python
ENVIRONMENT = Environment(
    extensions=[&amp;#34;jinja2.ext.do&amp;#34;, &amp;#34;jinja2.ext.loopcontrols&amp;#34;, &amp;#34;jinja2.ext.debug&amp;#34;],
    trim_blocks=True,
    lstrip_blocks=True,
    loader=FileSystemLoader(TEMPLATES_PATH, followlinks=True),
)
```&lt;/p&gt;
&lt;p&gt;This creates an **unsandboxed** `jinja2.Environment` with two dangerous extensions:
- `jinja2.ext.do` — enables `{% do %}` tags that execute arbitrary Python expressions
- `jinja2.ext.debug` — exposes internal template engine state&lt;/p&gt;
&lt;p&gt;**Attack path:**&lt;/p&gt;
&lt;p&gt;1. **Attacker builds a bento** with `dockerfile_template` set in `bentofile.yaml`. During `bentoml build`, `DockerOptions.write_to_bento()` (`build_config.py:272-276`) copies the template file into the bento archive at `env/docker/Dockerfile.template`:&lt;/p&gt;
&lt;p&gt;```python
if self.dockerfile_template is not None:
    shutil.copy2(
        resolve_user_filepath(self.dockerfile_template, build_ctx),
        docker_fol…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: bentoml&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The Dockerfile generation function `generate_containerfile()` in `src/bentoml/_internal/container/generate.py` uses an unsandboxed `jinja2.Environment` with the `jinja2.ext.do` extension to render user-provided `dockerfile_template` files. When a victim imports a malicious bento archive and runs `bentoml containerize`, attacker-controlled Jinja2 template code executes arbitrary Python directly on the host machine, bypassing all container isolation.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;The vulnerability exists in the `generate_containerfile()` function at `src/bentoml/_internal/container/generate.py:155-157`:&lt;/p&gt;
&lt;p&gt;```python
ENVIRONMENT = Environment(
    extensions=[&amp;#34;jinja2.ext.do&amp;#34;, &amp;#34;jinja2.ext.loopcontrols&amp;#34;, &amp;#34;jinja2.ext.debug&amp;#34;],
    trim_blocks=True,
    lstrip_blocks=True,
    loader=FileSystemLoader(TEMPLATES_PATH, followlinks=True),
)
```&lt;/p&gt;
&lt;p&gt;This creates an **unsandboxed** `jinja2.Environment` with two dangerous extensions:
- `jinja2.ext.do` — enables `{% do %}` tags that execute arbitrary Python expressions
- `jinja2.ext.debug` — exposes internal template engine state&lt;/p&gt;
&lt;p&gt;**Attack path:**&lt;/p&gt;
&lt;p&gt;1. **Attacker builds a bento** with `dockerfile_template` set in `bentofile.yaml`. During `bentoml build`, `DockerOptions.write_to_bento()` (`build_config.py:272-276`) copies the template file into the bento archive at `env/docker/Dockerfile.template`:&lt;/p&gt;
&lt;p&gt;```python
if self.dockerfile_template is not None:
    shutil.copy2(
        resolve_user_filepath(self.dockerfile_template, build_ctx),
        docker_fol…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-v959-cwq9-7hr6</guid>
    </item>
    <item>
      <title>PYSEC-2026-159</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2026-159</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: bentoml&lt;/p&gt;
&lt;p&gt;BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4.38, the Dockerfile generation function generate_containerfile() in src/bentoml/_internal/container/generate.py uses an unsandboxed jinja2.Environment with the jinja2.ext.do extension to render user-provided dockerfile_template files. When a victim imports a malicious bento archive and runs bentoml containerize, attacker-controlled Jinja2 template code executes arbitrary Python directly on the host machine, bypassing all container isolation. This vulnerability is fixed in 1.4.38.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: bentoml&lt;/p&gt;
&lt;p&gt;BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4.38, the Dockerfile generation function generate_containerfile() in src/bentoml/_internal/container/generate.py uses an unsandboxed jinja2.Environment with the jinja2.ext.do extension to render user-provided dockerfile_template files. When a victim imports a malicious bento archive and runs bentoml containerize, attacker-controlled Jinja2 template code executes arbitrary Python directly on the host machine, bypassing all container isolation. This vulnerability is fixed in 1.4.38.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2026-159</guid>
    </item>
  </channel>
</rss>
