Database/AI/ML frameworks & serving
BentoML OpenLLM 0.6.30 (async_run_command in src/openllm/common.py): A model repository directory name flows unescaped
Impact
A model repository directory name flows unescaped into a shell command, so a crafted repository name executes attacker commands as the user running OpenLLM. The exploit is public and, as of the advisory, the project had not responded to the report.
Who can reach it
A local user of OpenLLM who adds or uses a model repository with an attacker-chosen directory name. Requires local access and low privileges.
What to do
No vendor fix is confirmed. Do not pass untrusted repository paths to OpenLLM, run it as an unprivileged user in a container, and track the upstream issue before treating it as remediated.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.