---
id: CVE-2026-15035
aliases:
  - PYSEC-2026-2089
title: >-
  A vulnerability was found in bentoml OpenLLM 0.6.30. This affects the function
  async_run_command of the file src/openllm/common.py of the…
summary: >-
  A vulnerability was found in bentoml OpenLLM 0.6.30. This affects the function
  async_run_command of the file src/openllm/common.py of the component Model
  Repository Directory Name Handler. Performing a manipulation of the argument
  cmd re…
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
vendor: bentoml
product: bentoml
ecosystem: pip
affected:
  - bentoml <= 0.6.30
published: '2026-07-08'
updated: '2026-07-10'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/PYSEC-2026-2089'
references:
  - url: 'https://github.com/bentoml/OpenLLM/'
  - url: 'https://vuldb.com/cve/CVE-2026-15035'
  - url: 'https://vuldb.com/vuln/376786'
  - url: 'https://vuldb.com/vuln/376786/cti'
  - url: 'https://github.com/bentoml/OpenLLM/issues/1229'
  - url: 'https://github.com/bentoml/OpenLLM/pull/1235'
  - url: 'https://vuldb.com/submit/850895'
tags:
  - osv
  - pip
epss: 0.0222
epssPercentile: 0.81933
ingestedAt: '2026-07-10T18:56:50.623Z'
---

## Overview

A vulnerability was found in bentoml OpenLLM 0.6.30. This affects the function async_run_command of the file src/openllm/common.py of the component Model Repository Directory Name Handler. Performing a manipulation of the argument cmd results in command injection. Attacking locally is a requirement. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet.

## Affected packages

- `bentoml <= 0.6.30`

## Remediation

Refer to the advisory for the patched release.
