CVE-2024-2912
An insecure deserialization vulnerability exists in the BentoML framework, allowing remote code execution (RCE) by sending a specially crafted POST request. By exploiting this vulnerability, attackers can execute arbitrary commands on the server hosting the BentoML application. The vulnerability is triggered when a serialized object, crafted to execute OS commands upon deserialization, is sent to any valid BentoML endpoint. This issue poses a significant security risk, enabling attackers to compromise the server and potentially gain unauthorized access or control.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 10
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
- EPSS probability
- 1.51%
- CWE
- CWE-1188
- Published
- 2024-04-16
- Last modified
- 2026-03-13
Affected products
- bentoml bentoml/bentoml
Weakness type
Related vulnerabilities
- CVE-2023-27524 — Apache Superset: Session validation vulnerability when using provided default SECRET_KEY
- CVE-2022-24706 — Remote Code Execution Vulnerability in Packaging
- CVE-2023-6448 — Unitronics VisiLogic uses a default administrative password
- CVE-2021-41192 — Insecure default configuration
- CVE-2026-47668 — DbGate: Unauthenticated Remote Code Execution via JSON Script Runner
- CVE-2026-52824 — Kimai: Default APP_SECRET in Docker Image Enables Cookie Forgery and Account Takeover
- CVE-2026-31957 — Himmelblau unset domain configuration can allow any-tenant authentication at first login for remote deployments
- CVE-2026-28775 — Unauthenticated RCE via SNMP Default Writable Community String