CVE-2026-27905: 
Python vulnerability analysis and mitigation

Overview

CVE-2026-27905 is an arbitrary file write vulnerability via symlink path traversal in BentoML's tar extraction logic, affecting all versions prior to 1.4.36. The flaw resides in the safe_extract_tarfile() function in src/bentoml/_internal/utils/filesystem.py, which validates a tar member's own path but fails to validate symlink targets, enabling writes outside the intended extraction directory. It was published on March 3, 2026, by GitHub Security Advisory GHSA-m6w7-qv66-g3mf. The vulnerability carries a CVSS v4.0 base score of 8.6 (High) and a CVSS v3.1 score of 7.8 (High) (Github Advisory, BentoML Advisory).

Technical details

The root cause is classified as CWE-59 (Improper Link Resolution Before File Access / 'Link Following') and CWE-22 (Path Traversal). In filesystem.py lines 58–96, the function calls os.path.abspath() to check whether a tar member's path is within the destination directory, but os.path.abspath() does not resolve symlinks — only . and .. components. As a result, when a symlink member is extracted via tar._extract_member() (line 75), its linkname target (e.g., /etc) is never validated. A subsequent regular file entry named escape/<filename> passes the path check (its string path appears within the destination), but open(path, 'wb') follows the symlink and writes to the attacker-controlled location outside the extraction directory. The vulnerable callers are bento.py:542 and model.py:504, which invoke this function when pulling bentos or models from BentoCloud (BentoML Advisory, Patch Commit).

Impact

Successful exploitation allows an attacker to write arbitrary content to any file writable by the BentoML process on the host filesystem, including sensitive files such as ~/.bashrc, ~/.ssh/authorized_keys, crontabs, and Python site-packages. Overwriting shell initialization files or installed Python packages can escalate to remote code execution. In BentoCloud deployments, a malicious actor who publishes a crafted bento can compromise any system that subsequently pulls and extracts it, enabling broad lateral movement across an organization's ML infrastructure (BentoML Advisory).

Exploitability

A proof-of-concept Python script is publicly available in the GitHub Security Advisory, demonstrating creation of a malicious tar archive that triggers the symlink traversal and writes a file outside the extraction directory (BentoML Advisory). There is no evidence of in-the-wild exploitation at this time, and no threat actor attribution has been reported. The EPSS score is approximately 0.006% (1st percentile), indicating low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog (Github Advisory).

Exploitation steps

  1. Craft a malicious tar archive: Using Python's tarfile module, create a .tar.gz file containing two entries: (a) a symlink entry named escape with linkname pointing to an attacker-chosen directory outside the extraction path (e.g., /home/user/.ssh), and (b) a regular file entry named escape/authorized_keys with the desired payload content.
  2. Distribute the malicious bento/model: Upload the crafted tar archive as a BentoML bento or model to a shared repository or BentoCloud instance accessible to the target.
  3. Trigger extraction on the victim system: Induce the victim to pull the malicious bento (e.g., via bentoml pull or BentoCloud deployment), which calls safe_extract_tarfile() in bento.py:542 or model.py:504.
  4. Symlink is created without target validation: The function extracts the escape symlink entry via tar._extract_member(), creating a symlink inside the extraction directory pointing to the attacker-controlled external path. The symlink target is never checked against the destination boundary.
  5. File write through symlink: When the function processes the escape/authorized_keys entry, os.path.abspath() resolves the path string to within the extraction directory (passing the check), but open(path, 'wb') follows the symlink and writes the payload to the external target (e.g., /home/user/.ssh/authorized_keys).
  6. Achieve persistence or RCE: With an SSH authorized key injected, the attacker can authenticate to the host. Alternatively, overwriting Python site-packages or shell RC files achieves code execution on next invocation (BentoML Advisory, Patch Commit).

Indicators of compromise

  • File System: Unexpected symlinks within BentoML extraction directories (e.g., ~/.bentoml/bentos/<name>/) pointing to locations outside the bento directory; unexpected new or modified files in ~/.ssh/authorized_keys, ~/.bashrc, ~/.profile, crontab files, or Python site-packages directories with timestamps correlating to a bento pull operation.
  • Logs: BentoML log entries (if patched version is deployed) containing warnings such as "The tar file has a symlink ... pointing outside target directory" or "The tar file has a file ... resolving outside target directory"; system audit logs (auditd) showing file writes to sensitive paths by the BentoML process.
  • Process: Unexpected child processes spawned by the BentoML Python process following a bentoml pull or model download operation (e.g., new SSH sessions, shell interpreters, or network connections not initiated by the user).
  • Network: Outbound connections from the host to unexpected remote IPs shortly after a bento pull, potentially indicating a reverse shell or data exfiltration triggered by an overwritten script (BentoML Advisory).

Mitigation and workarounds

Upgrade BentoML to version 1.4.36 or later, which validates symlink targets against the destination directory before extraction and also resolves real paths of regular files to prevent writes through previously extracted symlinks (Patch Commit). Until patching is possible, avoid extracting bento or model tar archives from untrusted or unverified sources, and restrict the BentoML process to a least-privilege user account to limit the impact of any file write. Organizations using Python 3.12+ can also consider using tarfile.extractall(filter='data') as an alternative safe extraction method. Implement file integrity monitoring on sensitive directories to detect unauthorized modifications (BentoML Advisory).

Community reactions

The vulnerability was reported by security researcher q1uf3ng and published by BentoML maintainer frostming on March 3, 2026, via GitHub Security Advisory. The advisory includes a detailed proof-of-concept and remediation guidance, reflecting a responsible disclosure process. No significant broader media coverage or notable public researcher commentary beyond the advisory itself has been identified at this time (BentoML Advisory).

Additional resources


Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
CVE-2026-105782HIGH7.5
  • Python logoPython
  • scrapy
NoYesOct 06, 2026
GHSA-v853-p72q-4cfwHIGH7.5
  • Python logoPython
  • quart
NoYesOct 05, 2026
CVE-2026-105751MEDIUM6.9
  • Python logoPython
  • docling
NoYesOct 05, 2026
CVE-2026-105750MEDIUM5.9
  • Python logoPython
  • docling
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management