← Back to browse · API

CVE-2025-27520

Severity
CRITICAL
CVSS
9.8
EPSS
0.35674
Risk score
51.69
CISA KEV
No
PoC
Yes
Published
2025-04-04
Modified
2025-04-04
First seen
2026-08-07
Aliases
EUVD-2025-9752, GHSA-33XW-247W-6HMC, PYSEC-2026-294
Products
bentoml:BentoML 1.3.4, < 1.4.3
Sources
euvd EUVD-2025-9752
packetstorm f6d2b87d1592069625935586|CVE-2025-27520

Description

BentoML is a Python library for building online serving systems optimized for AI apps and model inference. A Remote Code Execution (RCE) vulnerability caused by insecure deserialization has been identified in the latest version (v1.4.2) of BentoML. It allows any unauthenticated user to execute arbitrary code on the server. It exists an unsafe code segment in serde.py. This vulnerability is fixed in 1.4.3.

References