OVERVIEW CVE-2026-35044 is a critical code injection vulnerability in BentoML versions prior to 1.4.38. The flaw exists in the Dockerfile generation function, which uses an unsandboxed Jinja2 template environment with unsafe extensions enabled. When a user imports a malicious bento archive and executes the containerize command, arbitrary Python code embedded in the dockerfile template executes directly on the host system with no container isolation. SEVERITY The vulnerability presents a critical risk with a CVSS score of 9.6. It requires no special privileges or authentication from the attacker, can be triggered via network means, and demands minimal interaction from the victim. The attack completely bypasses container security boundaries, granting the attacker the ability to compromise system confidentiality, integrity, and availability. The attack chain is straightforward, requiring only that a victim import a compromised bento archive. EXPLOITATION STATUS There is no evidence of active exploitation in the wild, as indicated by the vulnerability's absence from the CISA Known Exploited Vulnerabilities catalog. The exploit concept is practical and requires no complex preconditions beyond social engineering to distribute a malicious bento archive. Community attention remains minimal, reflected in the low EPSS score of 0.00016, suggesting the vulnerability has not yet gained significant traction among threat actors or researchers.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.4.38CPE matchmatch criteria | cpe:2.3:a:bentoml:bentoml:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.8 Bluesky, 0.5 Mastodon, and 1.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.