
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-33744 is a Dockerfile command injection vulnerability in BentoML caused by unsanitized interpolation of the docker.system_packages field in bentofile.yaml into Dockerfile RUN commands. It affects all BentoML versions up to and including 1.4.36, with version 1.4.37 containing the fix. The vulnerability was published on March 25, 2026 by researcher golang-not-rust via the BentoML security advisory program. It carries a CVSS v3.1 base score of 7.8 (High) (GitHub Advisory, BentoML Advisory).
The root cause (CWE-94: Improper Control of Generation of Code) lies in src/_bentoml_sdk/images.py (lines 85–89), where system_packages values are joined and string-formatted directly into shell install commands (e.g., apt-get install -q -y -o Dpkg::Options::=--force-confdef {packages}) without any escaping or validation. The Jinja2 template base_debian.j2 similarly uses {{ __options__system_packages | join(' ') }} without applying the bash_quote filter that exists in the codebase but is only used for environment variables. An attacker crafts a bentofile.yaml with a malicious entry such as "curl && id > /tmp/bentoml-pwned #" under docker.system_packages; when bentoml build and bentoml containerize are run, the injected shell commands execute during the Docker build process with root privileges (GitHub Advisory, BentoML Advisory).
Successful exploitation results in arbitrary code execution with the privileges of the Docker build process (typically root), giving an attacker full control over the build environment. This enables confidentiality breaches (access to secrets, model weights, credentials in the build context), integrity compromise (modification of build artifacts or the resulting container image), and availability disruption. The attack surface extends to CI/CD pipelines that automatically containerize BentoML projects, BentoCloud infrastructure building user-supplied configurations, and any developer who clones and builds a malicious ML repository — making this a significant supply chain risk (GitHub Advisory, BentoML Advisory).
A proof-of-concept exploit with step-by-step reproduction instructions is publicly available in the BentoML security advisory, including a specific crafted bentofile.yaml payload and commands to trigger RCE as root (BentoML Advisory). Exploitation requires user interaction — a victim must clone and run bentoml build / bentoml containerize on a malicious project — but no privileges are required of the attacker. The EPSS score is approximately 0.009% (1st percentile), and there is no evidence of in-the-wild exploitation or CISA KEV catalog listing at this time (GitHub Advisory).
service.py with a minimal BentoML service and a bentofile.yaml with a malicious system_packages entry, e.g.:service: "service:MyService"
docker:
system_packages:
- "curl && <malicious_command> #"bentoml build, which generates a Dockerfile containing the injected command in a RUN apt-get install ... line.bentoml containerize <service_name>, which invokes docker build. The injected shell command executes as root during the Docker build process./tmp/ (e.g., /tmp/bentoml-pwned) or other writable directories during a Docker build; modified or backdoored container images in the local Docker image store.RUN apt-get install lines (e.g., &&, |, ;, >, or backticks in package name positions); bentoml build output referencing unusual Dockerfile content.~/bentoml/bentos/<service_name>/<version>/env/docker/Dockerfile — malicious injection appears on the RUN apt-get install line with shell metacharacters in the package list.docker build (e.g., curl, wget, bash, python, nc) that are not typical for package installation (BentoML Advisory).Upgrade BentoML to version 1.4.37 or later, which addresses the vulnerability by adding input validation to system_packages in build_config.py (GitHub Advisory). As a workaround prior to patching, manually audit bentofile.yaml files from untrusted sources and ensure system_packages entries contain only valid package name characters (alphanumeric, dots, plus, hyphens, underscores, colons). Additionally, restrict CI/CD pipelines so that bentoml containerize is only run on reviewed and trusted bentofile.yaml configurations, and consider running Docker builds in isolated, ephemeral environments with limited privileges (BentoML Advisory).
The vulnerability was reported by researcher golang-not-rust and published by BentoML maintainer frostming on March 25, 2026. A Bluesky post referencing the CVE was observed in early April 2026, indicating some community awareness. Coverage appeared on threat intelligence aggregators including exploit-intel.com and thehackerwire.com shortly after disclosure (GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."