
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-27905 is an arbitrary file write vulnerability via symlink path traversal in BentoML's tar extraction logic, affecting all versions prior to 1.4.36. The flaw resides in the safe_extract_tarfile() function in src/bentoml/_internal/utils/filesystem.py, which validates a tar member's own path but fails to validate symlink targets, enabling writes outside the intended extraction directory. It was published on March 3, 2026, by GitHub Security Advisory GHSA-m6w7-qv66-g3mf. The vulnerability carries a CVSS v4.0 base score of 8.6 (High) and a CVSS v3.1 score of 7.8 (High) (Github Advisory, BentoML Advisory).
The root cause is classified as CWE-59 (Improper Link Resolution Before File Access / 'Link Following') and CWE-22 (Path Traversal). In filesystem.py lines 58–96, the function calls os.path.abspath() to check whether a tar member's path is within the destination directory, but os.path.abspath() does not resolve symlinks — only . and .. components. As a result, when a symlink member is extracted via tar._extract_member() (line 75), its linkname target (e.g., /etc) is never validated. A subsequent regular file entry named escape/<filename> passes the path check (its string path appears within the destination), but open(path, 'wb') follows the symlink and writes to the attacker-controlled location outside the extraction directory. The vulnerable callers are bento.py:542 and model.py:504, which invoke this function when pulling bentos or models from BentoCloud (BentoML Advisory, Patch Commit).
Successful exploitation allows an attacker to write arbitrary content to any file writable by the BentoML process on the host filesystem, including sensitive files such as ~/.bashrc, ~/.ssh/authorized_keys, crontabs, and Python site-packages. Overwriting shell initialization files or installed Python packages can escalate to remote code execution. In BentoCloud deployments, a malicious actor who publishes a crafted bento can compromise any system that subsequently pulls and extracts it, enabling broad lateral movement across an organization's ML infrastructure (BentoML Advisory).
A proof-of-concept Python script is publicly available in the GitHub Security Advisory, demonstrating creation of a malicious tar archive that triggers the symlink traversal and writes a file outside the extraction directory (BentoML Advisory). There is no evidence of in-the-wild exploitation at this time, and no threat actor attribution has been reported. The EPSS score is approximately 0.006% (1st percentile), indicating low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog (Github Advisory).
tarfile module, create a .tar.gz file containing two entries: (a) a symlink entry named escape with linkname pointing to an attacker-chosen directory outside the extraction path (e.g., /home/user/.ssh), and (b) a regular file entry named escape/authorized_keys with the desired payload content.bentoml pull or BentoCloud deployment), which calls safe_extract_tarfile() in bento.py:542 or model.py:504.escape symlink entry via tar._extract_member(), creating a symlink inside the extraction directory pointing to the attacker-controlled external path. The symlink target is never checked against the destination boundary.escape/authorized_keys entry, os.path.abspath() resolves the path string to within the extraction directory (passing the check), but open(path, 'wb') follows the symlink and writes the payload to the external target (e.g., /home/user/.ssh/authorized_keys).~/.bentoml/bentos/<name>/) pointing to locations outside the bento directory; unexpected new or modified files in ~/.ssh/authorized_keys, ~/.bashrc, ~/.profile, crontab files, or Python site-packages directories with timestamps correlating to a bento pull operation."The tar file has a symlink ... pointing outside target directory" or "The tar file has a file ... resolving outside target directory"; system audit logs (auditd) showing file writes to sensitive paths by the BentoML process.bentoml pull or model download operation (e.g., new SSH sessions, shell interpreters, or network connections not initiated by the user).Upgrade BentoML to version 1.4.36 or later, which validates symlink targets against the destination directory before extraction and also resolves real paths of regular files to prevent writes through previously extracted symlinks (Patch Commit). Until patching is possible, avoid extracting bento or model tar archives from untrusted or unverified sources, and restrict the BentoML process to a least-privilege user account to limit the impact of any file write. Organizations using Python 3.12+ can also consider using tarfile.extractall(filter='data') as an alternative safe extraction method. Implement file integrity monitoring on sensitive directories to detect unauthorized modifications (BentoML Advisory).
The vulnerability was reported by security researcher q1uf3ng and published by BentoML maintainer frostming on March 3, 2026, via GitHub Security Advisory. The advisory includes a detailed proof-of-concept and remediation guidance, reflecting a responsible disclosure process. No significant broader media coverage or notable public researcher commentary beyond the advisory itself has been identified at this time (BentoML Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."