VYPR

Openllm

by Bentoml

Source repositories

CVEs (2)

  • CVE-2024-8982MedMar 20, 2025
    risk 0.40cvss 6.2epss 0.01

    A Local File Inclusion (LFI) vulnerability in OpenLLM version 0.6.10 allows attackers to include files from the local server through the web application. This flaw could expose internal server files and potentially sensitive information such as configuration files, passwords,…

  • CVE-2026-15035MedJul 8, 2026
    risk 0.00cvss 5.3epss 0.02

    A vulnerability was found in bentoml OpenLLM 0.6.30. This affects the function async_run_command of the file src/openllm/common.py of the component Model Repository Directory Name Handler. Performing a manipulation of the argument cmd results in command injection. Attacking…