CVE-2026-24123: 
Python vulnerability analysis and mitigation

Overview

CVE-2026-24123 is a path traversal vulnerability in BentoML's bentofile.yaml configuration processing that allows arbitrary file read and exfiltration during the bentoml build process. It affects all BentoML versions prior to 1.4.34 (pip package bentoml < 1.4.34). The vulnerability was published on January 26, 2026, with a patch released the same day. The GitHub Advisory Database assigns a CVSS v3.1 score of 7.4 (High) with Scope Changed, while the NVD records a score of 6.5 (Medium) — the discrepancy stems from differing scope assessments (GitHub Advisory, BentoML Security Advisory).

Technical details

The root cause is CWE-22 (Improper Limitation of a Pathname to a Restricted Directory). The vulnerable function resolve_user_filepath() in src/bentoml/_internal/utils/filesystem.py resolves user-supplied file paths using os.path.expanduser() and os.path.expandvars() but performs no containment check to ensure the resolved path remains within the build context directory. Four fields in bentofile.yaml are exploitable: description, docker.setup_script, docker.dockerfile_template, and conda.environment_yml. The description field supports absolute paths and relative traversal (e.g., file:/etc/passwd, file:../../../etc/passwd), while the docker.* and conda.* fields additionally support tilde expansion (~/.ssh/id_rsa) and environment variable expansion ($HOME/.aws/credentials). The /proc/self/environ vector is especially dangerous as it exposes all environment variables of the build process in a single payload (GitHub Advisory, BentoML Security Advisory).

Impact

Successful exploitation results in high confidentiality impact with no integrity or availability impact. An attacker who tricks a victim into running bentoml build on a malicious bentofile.yaml can silently embed arbitrary files — including SSH keys, AWS credentials, /etc/passwd, and all CI/CD pipeline secrets (e.g., AWS_SECRET_ACCESS_KEY, GITHUB_TOKEN, DATABASE_URL) — into the resulting bento archive. When the victim subsequently runs bentoml push, these exfiltrated files are uploaded to BentoCloud or shared registries, where any organization member or attacker with a compromised account can retrieve them, effectively turning BentoCloud into an unintentional exfiltration channel (GitHub Advisory, BentoML Security Advisory).

Exploitability

No public proof-of-concept exploit code has been observed, and there is no evidence of in-the-wild exploitation at this time (GitHub Advisory). The EPSS score is approximately 0.011–0.015% (3rd percentile), indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, exploitation is technically trivial — it requires only crafting a malicious bentofile.yaml and social engineering a victim to clone and build it, making supply chain abuse a realistic threat vector.

Exploitation steps

  1. Craft a malicious repository: Create a public or shared ML project repository containing a service.py (minimal BentoML service) and a weaponized bentofile.yaml with path traversal payloads in one or more vulnerable fields.
  2. Select attack vector: Choose the target file to exfiltrate. For CI/CD secret theft, use description: "file:/proc/self/environ". For SSH key theft, use docker.dockerfile_template: "~/.ssh/id_rsa". For AWS credentials, use docker.dockerfile_template: "$HOME/.aws/credentials".
  3. Example malicious bentofile.yaml (CI/CD secrets via description field):
service: "service.py:TestService"
description: "file:/proc/self/environ"
  1. Social engineer the victim: Convince the target (e.g., via a pull request, open-source contribution, or shared repository link) to clone the repository and run bentoml build.
  2. Trigger exfiltration: When the victim runs bentoml build, BentoML copies the targeted file into the bento archive (e.g., as README.md for the description field, or env/docker/Dockerfile.template for dockerfile_template).
  3. Retrieve stolen data: If the victim runs bentoml push, the bento (containing the exfiltrated file) is uploaded to BentoCloud or a shared registry. The attacker, with any level of organization access, downloads the bento and extracts the embedded secrets:
# Extract CI/CD secrets from the bento archive
cat ~/bentoml/bentos/test_service/abc123/README.md | tr '\0' '\n' | grep -E "KEY|TOKEN|SECRET"

(GitHub Advisory, BentoML Security Advisory)

Indicators of compromise

  • File System: Unexpected or suspicious content in bento archive files — specifically README.md, env/docker/setup_script, env/docker/Dockerfile.template, or env/conda/environment.yml — containing system file contents (e.g., /etc/passwd entries, environment variable dumps, SSH key material, or AWS credential blocks).
  • File System: Bento archives located at ~/bentoml/bentos/<service>/<tag>/ where the above files contain data inconsistent with the project's legitimate description or Docker configuration.
  • Logs: BentoML build logs referencing file paths outside the project directory (e.g., /etc/, /proc/, ~/.ssh/, ~/.aws/) during the build process.
  • Network: Unexpected bentoml push operations uploading bentos to BentoCloud or external registries from CI/CD pipelines, particularly following a repository clone or pull request merge.
  • Process: The bentoml build process accessing files such as /proc/self/environ, /etc/passwd, ~/.ssh/id_rsa, or ~/.aws/credentials — detectable via auditd or strace monitoring of file open syscalls during the build.

Mitigation and workarounds

Upgrade BentoML to version 1.4.34 or later, which adds path containment enforcement to resolve_user_filepath() — blocking absolute paths, paths outside the current working directory, hidden files, and access to system directories (/etc, /proc) when secure=True (BentoML Release v1.4.34, Patch Commit). As an immediate workaround, never run bentoml build on bentofile.yaml files from untrusted or unreviewed sources. Audit all bentos previously built from potentially malicious bentofiles — especially those pushed to BentoCloud or shared registries — and rotate any secrets that may have been exposed. Implement mandatory code review for bentofile.yaml changes in CI/CD pipelines and restrict BentoCloud organization access to minimize the blast radius of any exfiltration.

Community reactions

The vulnerability was reported by security researcher logicx24 and published by BentoML maintainer frostming on January 26, 2026, with a same-day patch release (GitHub Advisory). The CISA vulnerability bulletin for the week of January 26, 2026 included this CVE in its summary. Qualys added detection for this vulnerability (detection IDs 5007203 and 530871) and included it in their January 2026 application security detections publication. No significant broader media coverage or notable social media discussion has been identified beyond standard vulnerability aggregator postings.

Additional resources


Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
CVE-2026-105782HIGH7.5
  • Python logoPython
  • scrapy
NoYesOct 06, 2026
GHSA-v853-p72q-4cfwHIGH7.5
  • Python logoPython
  • quart
NoYesOct 05, 2026
CVE-2026-105751MEDIUM6.9
  • Python logoPython
  • docling
NoYesOct 05, 2026
CVE-2026-105750MEDIUM5.9
  • Python logoPython
  • docling
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management