VYPR
Medium severity5.3NVD Advisory· Published Jul 8, 2026· Updated Jul 9, 2026

CVE-2026-15035

CVE-2026-15035

Description

A vulnerability was found in bentoml OpenLLM 0.6.30. This affects the function async_run_command of the file src/openllm/common.py of the component Model Repository Directory Name Handler. Performing a manipulation of the argument cmd results in command injection. Attacking locally is a requirement. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet.

Affected products

2
  • Bentoml/Openllm2 versions
    cpe:2.3:a:bentoml:openllm:0.6.30:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:bentoml:openllm:0.6.30:*:*:*:*:*:*:*
    • (no CPE)range: =0.6.30

Patches

Vulnerability mechanics

References

6

News mentions

0

No linked articles in our index yet.