---
id: CVE-2026-33744
title: >-
  BentoML is a Python library for building online serving systems optimized for
  AI apps and model inference
summary: >-
  BentoML is a Python library for building online serving systems optimized for
  AI apps and model inference. Prior to 1.4.37, the `docker.system_packages`
  field in `bentofile.yaml` accepts arbitrary strings that are interpolated
  directly i…
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'
cwe:
  - CWE-94
vendor: bentoml
product: bentoml
affected:
  - bentoml < 1.4.37
patched:
  - bentoml 1.4.37
published: '2026-03-27'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T08:10:00.200'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-33744'
references:
  - url: 'https://github.com/bentoml/BentoML/security/advisories/GHSA-jfjg-vc52-wqvf'
    label: security-advisories@github.com
tags:
  - nvd
epss: 0.00249
epssPercentile: 0.14839
ingestedAt: '2026-10-07T08:20:03.906Z'
---

## Overview

BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4.37, the `docker.system_packages` field in `bentofile.yaml` accepts arbitrary strings that are interpolated directly into Dockerfile `RUN` commands without sanitization. Since `system_packages` is semantically a list of OS package names (data), users do not expect values to be interpreted as shell commands. A malicious `bentofile.yaml` achieves arbitrary command execution during `bentoml containerize` / `docker build`. Version 1.4.37 fixes the issue.

## Affected

- `bentoml < 1.4.37`

## Remediation

Upgrade past the affected range:

- `bentoml 1.4.37`
