CVE-2026-33744: 
Python vulnerability analysis and mitigation

Overview

CVE-2026-33744 is a Dockerfile command injection vulnerability in BentoML caused by unsanitized interpolation of the docker.system_packages field in bentofile.yaml into Dockerfile RUN commands. It affects all BentoML versions up to and including 1.4.36, with version 1.4.37 containing the fix. The vulnerability was published on March 25, 2026 by researcher golang-not-rust via the BentoML security advisory program. It carries a CVSS v3.1 base score of 7.8 (High) (GitHub Advisory, BentoML Advisory).

Technical details

The root cause (CWE-94: Improper Control of Generation of Code) lies in src/_bentoml_sdk/images.py (lines 85–89), where system_packages values are joined and string-formatted directly into shell install commands (e.g., apt-get install -q -y -o Dpkg::Options::=--force-confdef {packages}) without any escaping or validation. The Jinja2 template base_debian.j2 similarly uses {{ __options__system_packages | join(' ') }} without applying the bash_quote filter that exists in the codebase but is only used for environment variables. An attacker crafts a bentofile.yaml with a malicious entry such as "curl && id > /tmp/bentoml-pwned #" under docker.system_packages; when bentoml build and bentoml containerize are run, the injected shell commands execute during the Docker build process with root privileges (GitHub Advisory, BentoML Advisory).

Impact

Successful exploitation results in arbitrary code execution with the privileges of the Docker build process (typically root), giving an attacker full control over the build environment. This enables confidentiality breaches (access to secrets, model weights, credentials in the build context), integrity compromise (modification of build artifacts or the resulting container image), and availability disruption. The attack surface extends to CI/CD pipelines that automatically containerize BentoML projects, BentoCloud infrastructure building user-supplied configurations, and any developer who clones and builds a malicious ML repository — making this a significant supply chain risk (GitHub Advisory, BentoML Advisory).

Exploitability

A proof-of-concept exploit with step-by-step reproduction instructions is publicly available in the BentoML security advisory, including a specific crafted bentofile.yaml payload and commands to trigger RCE as root (BentoML Advisory). Exploitation requires user interaction — a victim must clone and run bentoml build / bentoml containerize on a malicious project — but no privileges are required of the attacker. The EPSS score is approximately 0.009% (1st percentile), and there is no evidence of in-the-wild exploitation or CISA KEV catalog listing at this time (GitHub Advisory).

Exploitation steps

  1. Craft malicious repository: Create a BentoML project repository containing a service.py with a minimal BentoML service and a bentofile.yaml with a malicious system_packages entry, e.g.:
service: "service:MyService"
docker:
  system_packages:
    - "curl && <malicious_command> #"
  1. Publish or share the repository: Upload the project to a public or shared repository (e.g., GitHub, Hugging Face Hub, or a shared BentoML model registry) to target developers or automated pipelines.
  2. Victim clones and builds: The victim (or a CI/CD pipeline) clones the repository and runs bentoml build, which generates a Dockerfile containing the injected command in a RUN apt-get install ... line.
  3. Trigger code execution: The victim runs bentoml containerize <service_name>, which invokes docker build. The injected shell command executes as root during the Docker build process.
  4. Achieve objective: The attacker's payload runs with root privileges inside the Docker build context, enabling exfiltration of secrets, installation of backdoors in the resulting image, or further lateral movement (BentoML Advisory).

Indicators of compromise

  • File System: Unexpected files created in /tmp/ (e.g., /tmp/bentoml-pwned) or other writable directories during a Docker build; modified or backdoored container images in the local Docker image store.
  • Logs: Docker build logs containing unexpected shell commands within RUN apt-get install lines (e.g., &&, |, ;, >, or backticks in package name positions); bentoml build output referencing unusual Dockerfile content.
  • File System (Dockerfile artifact): Inspect the generated Dockerfile at ~/bentoml/bentos/<service_name>/<version>/env/docker/Dockerfile — malicious injection appears on the RUN apt-get install line with shell metacharacters in the package list.
  • Process: Unexpected child processes spawned during docker build (e.g., curl, wget, bash, python, nc) that are not typical for package installation (BentoML Advisory).

Mitigation and workarounds

Upgrade BentoML to version 1.4.37 or later, which addresses the vulnerability by adding input validation to system_packages in build_config.py (GitHub Advisory). As a workaround prior to patching, manually audit bentofile.yaml files from untrusted sources and ensure system_packages entries contain only valid package name characters (alphanumeric, dots, plus, hyphens, underscores, colons). Additionally, restrict CI/CD pipelines so that bentoml containerize is only run on reviewed and trusted bentofile.yaml configurations, and consider running Docker builds in isolated, ephemeral environments with limited privileges (BentoML Advisory).

Community reactions

The vulnerability was reported by researcher golang-not-rust and published by BentoML maintainer frostming on March 25, 2026. A Bluesky post referencing the CVE was observed in early April 2026, indicating some community awareness. Coverage appeared on threat intelligence aggregators including exploit-intel.com and thehackerwire.com shortly after disclosure (GitHub Advisory).

Additional resources


Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
CVE-2026-105782HIGH7.5
  • Python logoPython
  • scrapy
NoYesOct 06, 2026
GHSA-v853-p72q-4cfwHIGH7.5
  • Python logoPython
  • quart
NoYesOct 05, 2026
CVE-2026-105751MEDIUM6.9
  • Python logoPython
  • docling
NoYesOct 05, 2026
CVE-2026-105750MEDIUM5.9
  • Python logoPython
  • docling
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management