<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Thu, 08 Oct 2026 07:24:54 +0000</lastBuildDate>
    <item>
      <title>CVE-2025-32375 — Insecure Deserialization leads to RCE in BentoML's runner server</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2025-32375</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; BentoML&lt;/p&gt;
&lt;p&gt;BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4.8, there was an insecure deserialization in BentoML&amp;#39;s runner server. By setting specific headers and parameters in the POST request, it is possible to execute any unauthorized arbitrary code on the server, which will grant the attackers to have the initial access and information disclosure on the server. This vulnerability is fixed in 1.4.8.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; BentoML&lt;/p&gt;
&lt;p&gt;BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4.8, there was an insecure deserialization in BentoML&amp;#39;s runner server. By setting specific headers and parameters in the POST request, it is possible to execute any unauthorized arbitrary code on the server, which will grant the attackers to have the initial access and information disclosure on the server. This vulnerability is fixed in 1.4.8.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2025-32375</guid>
    </item>
    <item>
      <title>GHSA-7v4r-c989-xh26 — BentoML's runner server Vulnerable to Remote Code Execution (RCE) via Insecure Deserialization</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-7v4r-c989-xh26</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: bentoml&lt;/p&gt;
&lt;p&gt;### Summary
There was an insecure deserialization in BentoML&amp;#39;s runner server. By setting specific headers and parameters in the POST request, it is possible to execute any unauthorized arbitrary code on the server, which will grant the attackers to have the initial access and information disclosure on the server.&lt;/p&gt;
&lt;p&gt;### PoC
 - First, create a file named **model.py** to create a simple model and save it
```
import bentoml
import numpy as np&lt;/p&gt;
&lt;p&gt;class mymodel:
    def predict(self, info):
        return np.abs(info)
    def __call__(self, info):
        return self.predict(info)&lt;/p&gt;
&lt;p&gt;model = mymodel()
bentoml.picklable_model.save_model(&amp;#34;mymodel&amp;#34;, model)
```
- Then run the following command to save this model
```
python3 model.py
```
- Next, create **bentofile.yaml** to build this model
```
service: &amp;#34;service.py&amp;#34;  
description: &amp;#34;A model serving service with BentoML&amp;#34;  
python:
  packages:
    - bentoml
    - numpy
models:
  - tag: MyModel:latest  
include:
  - &amp;#34;*.py&amp;#34;  
```
- Then, create **service.py** to host this model
```
import bentoml
from bentoml.io import NumpyNdarray
import numpy as np&lt;/p&gt;
&lt;p&gt;model_runner = bentoml.picklable_model.get(&amp;#34;mymodel:latest&amp;#34;).to_runner()&lt;/p&gt;
&lt;p&gt;svc = bentoml.Service(&amp;#34;myservice&amp;#34;, runners=[model_runner])&lt;/p&gt;
&lt;p&gt;async def predict(input_data: np.ndarray):&lt;/p&gt;
&lt;p&gt;input_columns = np.split(input_data, input_data.shape[1], axis=1)
    result_generator = model_runner.async_run(input_columns, is_stream=True)
    async for result in result_generator:
        yield result
```
- Then,…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: bentoml&lt;/p&gt;
&lt;p&gt;### Summary
There was an insecure deserialization in BentoML&amp;#39;s runner server. By setting specific headers and parameters in the POST request, it is possible to execute any unauthorized arbitrary code on the server, which will grant the attackers to have the initial access and information disclosure on the server.&lt;/p&gt;
&lt;p&gt;### PoC
 - First, create a file named **model.py** to create a simple model and save it
```
import bentoml
import numpy as np&lt;/p&gt;
&lt;p&gt;class mymodel:
    def predict(self, info):
        return np.abs(info)
    def __call__(self, info):
        return self.predict(info)&lt;/p&gt;
&lt;p&gt;model = mymodel()
bentoml.picklable_model.save_model(&amp;#34;mymodel&amp;#34;, model)
```
- Then run the following command to save this model
```
python3 model.py
```
- Next, create **bentofile.yaml** to build this model
```
service: &amp;#34;service.py&amp;#34;  
description: &amp;#34;A model serving service with BentoML&amp;#34;  
python:
  packages:
    - bentoml
    - numpy
models:
  - tag: MyModel:latest  
include:
  - &amp;#34;*.py&amp;#34;  
```
- Then, create **service.py** to host this model
```
import bentoml
from bentoml.io import NumpyNdarray
import numpy as np&lt;/p&gt;
&lt;p&gt;model_runner = bentoml.picklable_model.get(&amp;#34;mymodel:latest&amp;#34;).to_runner()&lt;/p&gt;
&lt;p&gt;svc = bentoml.Service(&amp;#34;myservice&amp;#34;, runners=[model_runner])&lt;/p&gt;
&lt;p&gt;async def predict(input_data: np.ndarray):&lt;/p&gt;
&lt;p&gt;input_columns = np.split(input_data, input_data.shape[1], axis=1)
    result_generator = model_runner.async_run(input_columns, is_stream=True)
    async for result in result_generator:
        yield result
```
- Then,…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-7v4r-c989-xh26</guid>
    </item>
  </channel>
</rss>
