Skip to content

Security: 8 pending GHSA advisories awaiting maintainer triage (submitted 2026-05-26) #5641

Description

@skyvast404

Hi BentoML team,

I submitted 8 security advisories on 2026-05-26 via the GitHub Security Advisory workflow.
All 8 are still in Triage state with no maintainer engagement after ~30 days.

Posting here (not in the advisories themselves) because maintainers are not subscribed
to advisory comments by default — I want to make sure this lands in your notifications.

Advisories pending review (full details visible to maintainers only):

GHSA Severity CVSS Topic
GHSA-rpc7-x8h4-rmfp Critical 9.8 Insecure deserialization in remote runner client
GHSA-68f9-9v8g-6f74 Critical 9.1 ServiceContext bypass in API endpoint handler
GHSA-2mcr-m9qx-5vwr High 8.1 Unauthenticated deserialization via Content-Type
GHSA-xf8h-hp2h-j59q High 8.1 cloudpickle deserialization in registry assets
GHSA-fv49-5c3q-vm6c High 7.8 Dockerfile injection (distinct from CVE-2026-44346)
GHSA-733m-579v-4gv9 High 7.8 Shell injection in Conda env creation
GHSA-g5mv-f966-5wcj High 7.0 Working-directory check bypass in import_service
GHSA-qx46-5748-3f39 Medium 5.5 Cloud API token written world-readable

Each advisory includes:

  • Vulnerable code path (file:line, verified on bentoml==1.4.39)
  • Minimal reproduction
  • Suggested fix

Happy to help with:

  • Deduplication if any overlap with internal findings
  • Prioritization by exploitability
  • Draft PRs for fixes if useful

I'd appreciate any signal — even "we'll get to this in N weeks" — so I can plan
disclosure timing accordingly. Following industry-standard 90-day disclosure
(would land around 2026-08-24).

cc @parano @aarnphm @ssheng @larme

Thanks,
skyvast404 / 京东 AI 安全实验室

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions