Intel

AIKIDO-2025-10137

bentoml is vulnerable to Unsafe Deserialization

Unsafe DeserializationCVE-2025-27520 Published Mar 6, 2025

95

Critical Risk

This Affects:

PYTHONbentoml
1.2.0 - 1.4.2
Fixed in 1.4.3
Are you affected? Scan for Free

TL;DR

Affected versions of this package enable pickling encoding on the main server, which can be exploited by attackers to execute unsafe operations, potentially leading to security vulnerabilities like Remote Code Execution (RCE).

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

bentoml is vulnerable to Unsafe Deserialization in versions 1.2.0 - 1.4.2.

How to fix this

Upgrade the bentoml library to the patch version.