{"id":"CVE-2026-44346","aliases":["GHSA-w2pm-x38x-jp44","PYSEC-2026-190"],"url":"https://o3.security/vulnerability/CVE-2026-44346","summary":"BentoML: Dockerfile command injection via envs[*].name in bentofile.yaml","details":"BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4.39, a malicious bentofile.yaml containing a newline-injected value in envs[*].name produces unquoted RUN directives in the BentoML-generated Dockerfile. When the victim runs bentoml containerize on the imported bento, those RUN directives execute on the host during docker build. This vulnerability is fixed in 1.4.39.","published":"2026-05-27T17:22:47.101Z","modified":"2026-07-15T01:49:06.941057671Z","cvss":{"score":8.8,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"bentoml","fixedVersion":"1.4.39"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/44xxx/CVE-2026-44346.json"},{"type":"ADVISORY","url":"https://github.com/bentoml/BentoML/security/advisories/GHSA-w2pm-x38x-jp44"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-44346"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-15T01:49:06.941057671Z"}}