Raw vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HSummary
CVE-2026-35043 is a high-severity OS Command Injection (CWE-78) vulnerability in Bentoml Bentoml. Its CVSS base score is 7.8 (High).
Operationally, exploitation aligns with the MITRE ATT&CK technique Command and Scripting Interpreter (T1059); ranked at the 24th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog; a public proof-of-concept is referenced.
This vulnerability is AI-related — categorised as NLP and Transformers; in the Supply Chain and Deployment risk domain.
The strongest mitigations our analysis identified map to SA-11 (Developer Testing and Evaluation) and SI-10 (Information Input Validation) — see the control section below for these in your framework.
Deeper analysis AI-assisted summary
Synthesised by an AI model from the NVD description and linked references — a reading aid, not an authoritative source.
CVE-2026-35043 is a command injection vulnerability (CWE-78) in BentoML, an open-source Python library for building online serving systems optimized for AI applications and model inference. The issue affects versions prior to 1.4.38 and resides in the cloud deployment path at src/bentoml/_internal/cloud/deployment.py. Specifically, line 1648 interpolates the user-specified system_packages directly into a shell command using an f-string without proper quoting or sanitization. This flaw was not addressed in the prior fix for CVE-2026-33744. The vulnerability carries a CVSS v3.1 base score of 7.8 (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H) and was published on 2026-04-06.
An attacker can exploit this vulnerability by supplying a malicious system_packages value during a BentoCloud deployment. The tainted input generates a setup.sh script that is uploaded and executed on BentoCloud's cloud build infrastructure, enabling remote code execution on the CI/CD tier. Exploitation requires local access to run the BentoML deployment command (aligning with the local attack vector), no privileges, low complexity, and user interaction to initiate the deployment, but results in high confidentiality, integrity, and availability impacts on the remote infrastructure.
The BentoML security advisory at https://github.com/bentoml/BentoML/security/advisories/GHSA-fgv4-6jr3-jgfw confirms the vulnerability and states that it is fixed in version 1.4.38. Security practitioners should advise users to upgrade to BentoML 1.4.38 or later to mitigate the risk.
This vulnerability is particularly relevant for AI/ML workflows, as BentoML is designed for serving AI models, and exploitation could compromise cloud CI/CD pipelines handling model inference deployments. No public information on real-world exploitation is available.
OWASP Top 10 for Web (2025)
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2026-19384
Vulnerability Data
BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4.38, the cloud deployment path in src/bentoml/_internal/cloud/deployment.py was not included in the fix for CVE-2026-33744. Line 1648 interpolates system_packages directly into…
more
a shell command using an f-string without any quoting. The generated script is uploaded to BentoCloud as setup.sh and executed on the cloud build infrastructure during deployment, making this a remote code execution on the CI/CD tier. This vulnerability is fixed in 1.4.38.
- CWE(s)
AI Security AnalysisAI
- AI Category
- NLP and Transformers
- Risk Domain
- Supply Chain and Deployment
- OWASP Top 10 for LLMs 2025
- None mapped
- Classification Reason
- Matched keywords: ai, bentoml
Related Threats
MITRE ATT&CK Enterprise Techniques
CVEs Like This One
Affected Assets
Mitigating Controls
Control response
—
—
—
V1.2.5V1.2.8V15.2.5
Mitigating Controls (NIST 800-53 r5) AI
Developer testing and evaluation can discover missing or incorrect command sanitization during development.
Input validation directly neutralizes or rejects special characters that would otherwise alter OS command structure.
Least privilege reduces the permissions available to any process that could be subverted by injected commands.
Least functionality restricts available OS commands and interpreters, limiting the blast radius of injection.
Secure engineering principles require proper neutralization of untrusted input before command construction.
Mitigating Controls (NIST CSF 2.0) AI
Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→CSF cross-walk (authority under review) — links open the control.
PR.PS-06's SDLC practices directly require secure coding and input handling that blocks command-injection defects, yet the single broad outcome leaves many specific neutralization vectors and verification gaps unaddressed.
Routine patching/maintenance can remediate known command-injection CVEs in dependencies (partial forward) but does nothing to stop developers from introducing improper neutralization in custom code (none reverse).
Mitigating Controls (ISO/IEC 27001:2022 Annex A) AI
Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→ISO cross-walk (authority under review) — links open the control.
Security testing and code review target insecure use of operating-system command interfaces, catching command-injection flaws introduced during development.