
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-24123 is a path traversal vulnerability in BentoML's bentofile.yaml configuration processing that allows arbitrary file read and exfiltration during the bentoml build process. It affects all BentoML versions prior to 1.4.34 (pip package bentoml < 1.4.34). The vulnerability was published on January 26, 2026, with a patch released the same day. The GitHub Advisory Database assigns a CVSS v3.1 score of 7.4 (High) with Scope Changed, while the NVD records a score of 6.5 (Medium) — the discrepancy stems from differing scope assessments (GitHub Advisory, BentoML Security Advisory).
The root cause is CWE-22 (Improper Limitation of a Pathname to a Restricted Directory). The vulnerable function resolve_user_filepath() in src/bentoml/_internal/utils/filesystem.py resolves user-supplied file paths using os.path.expanduser() and os.path.expandvars() but performs no containment check to ensure the resolved path remains within the build context directory. Four fields in bentofile.yaml are exploitable: description, docker.setup_script, docker.dockerfile_template, and conda.environment_yml. The description field supports absolute paths and relative traversal (e.g., file:/etc/passwd, file:../../../etc/passwd), while the docker.* and conda.* fields additionally support tilde expansion (~/.ssh/id_rsa) and environment variable expansion ($HOME/.aws/credentials). The /proc/self/environ vector is especially dangerous as it exposes all environment variables of the build process in a single payload (GitHub Advisory, BentoML Security Advisory).
Successful exploitation results in high confidentiality impact with no integrity or availability impact. An attacker who tricks a victim into running bentoml build on a malicious bentofile.yaml can silently embed arbitrary files — including SSH keys, AWS credentials, /etc/passwd, and all CI/CD pipeline secrets (e.g., AWS_SECRET_ACCESS_KEY, GITHUB_TOKEN, DATABASE_URL) — into the resulting bento archive. When the victim subsequently runs bentoml push, these exfiltrated files are uploaded to BentoCloud or shared registries, where any organization member or attacker with a compromised account can retrieve them, effectively turning BentoCloud into an unintentional exfiltration channel (GitHub Advisory, BentoML Security Advisory).
No public proof-of-concept exploit code has been observed, and there is no evidence of in-the-wild exploitation at this time (GitHub Advisory). The EPSS score is approximately 0.011–0.015% (3rd percentile), indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, exploitation is technically trivial — it requires only crafting a malicious bentofile.yaml and social engineering a victim to clone and build it, making supply chain abuse a realistic threat vector.
service.py (minimal BentoML service) and a weaponized bentofile.yaml with path traversal payloads in one or more vulnerable fields.description: "file:/proc/self/environ". For SSH key theft, use docker.dockerfile_template: "~/.ssh/id_rsa". For AWS credentials, use docker.dockerfile_template: "$HOME/.aws/credentials".bentofile.yaml (CI/CD secrets via description field):service: "service.py:TestService"
description: "file:/proc/self/environ"bentoml build.bentoml build, BentoML copies the targeted file into the bento archive (e.g., as README.md for the description field, or env/docker/Dockerfile.template for dockerfile_template).bentoml push, the bento (containing the exfiltrated file) is uploaded to BentoCloud or a shared registry. The attacker, with any level of organization access, downloads the bento and extracts the embedded secrets:# Extract CI/CD secrets from the bento archive
cat ~/bentoml/bentos/test_service/abc123/README.md | tr '\0' '\n' | grep -E "KEY|TOKEN|SECRET"README.md, env/docker/setup_script, env/docker/Dockerfile.template, or env/conda/environment.yml — containing system file contents (e.g., /etc/passwd entries, environment variable dumps, SSH key material, or AWS credential blocks).~/bentoml/bentos/<service>/<tag>/ where the above files contain data inconsistent with the project's legitimate description or Docker configuration./etc/, /proc/, ~/.ssh/, ~/.aws/) during the build process.bentoml push operations uploading bentos to BentoCloud or external registries from CI/CD pipelines, particularly following a repository clone or pull request merge.bentoml build process accessing files such as /proc/self/environ, /etc/passwd, ~/.ssh/id_rsa, or ~/.aws/credentials — detectable via auditd or strace monitoring of file open syscalls during the build.Upgrade BentoML to version 1.4.34 or later, which adds path containment enforcement to resolve_user_filepath() — blocking absolute paths, paths outside the current working directory, hidden files, and access to system directories (/etc, /proc) when secure=True (BentoML Release v1.4.34, Patch Commit). As an immediate workaround, never run bentoml build on bentofile.yaml files from untrusted or unreviewed sources. Audit all bentos previously built from potentially malicious bentofiles — especially those pushed to BentoCloud or shared registries — and rotate any secrets that may have been exposed. Implement mandatory code review for bentofile.yaml changes in CI/CD pipelines and restrict BentoCloud organization access to minimize the blast radius of any exfiltration.
The vulnerability was reported by security researcher logicx24 and published by BentoML maintainer frostming on January 26, 2026, with a same-day patch release (GitHub Advisory). The CISA vulnerability bulletin for the week of January 26, 2026 included this CVE in its summary. Qualys added detection for this vulnerability (detection IDs 5007203 and 530871) and included it in their January 2026 application security detections publication. No significant broader media coverage or notable social media discussion has been identified beyond standard vulnerability aggregator postings.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."