{"id":"CVE-2026-15035","aliases":["PYSEC-2026-2089"],"url":"https://o3.security/vulnerability/CVE-2026-15035","summary":"bentoml OpenLLM Model Repository Directory Name common.py async_run_command command injection","details":"A vulnerability was found in bentoml OpenLLM 0.6.30. This affects the function async_run_command of the file src/openllm/common.py of the component Model Repository Directory Name Handler. Performing a manipulation of the argument cmd results in command injection. Attacking locally is a requirement. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet.","published":"2026-07-08T14:00:09.786Z","modified":"2026-08-12T03:51:24.697863230Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[],"fix":{"url":"https://github.com/bentoml/OpenLLM/pull/1235","label":"bentoml/OpenLLM#1235"},"references":[{"type":"WEB","url":"https://github.com/bentoml/OpenLLM/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/15xxx/CVE-2026-15035.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-15035"},{"type":"ADVISORY","url":"https://vuldb.com/cve/CVE-2026-15035"},{"type":"ADVISORY","url":"https://vuldb.com/submit/850895"},{"type":"ADVISORY","url":"https://vuldb.com/vuln/376786"},{"type":"REPORT","url":"https://github.com/bentoml/OpenLLM/issues/1229"},{"type":"REPORT","url":"https://vuldb.com/vuln/376786/cti"},{"type":"FIX","url":"https://github.com/bentoml/OpenLLM/pull/1235"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:24.697863230Z"}}