bentoml is vulnerable to Unsafe Deserialization
95
Critical Risk
Affected versions of this package enable pickling encoding on the main server, which can be exploited by attackers to execute unsafe operations, potentially leading to security vulnerabilities like Remote Code Execution (RCE).
You are affected if you are using a version that falls within the vulnerable range.
bentoml is vulnerable to Unsafe Deserialization in versions 1.2.0 - 1.4.2.
Upgrade the bentoml library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant