CVE-2025-32375 CRITICAL

CVE-2025-32375: Insecure Deserialization leads to RCE in BentoML's runner server

Vendor Bentoml
Product BentoML
Weakness CWE-502 · Unsafe deserialization
Published April 9, 2025
Last update April 9, 2025

CVSS base score

9.8/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

What the vulnerability does

01Description

BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4.8, there was an insecure deserialization in BentoML's runner server. By setting specific headers and parameters in the POST request, it is possible to execute any unauthorized arbitrary code on the server, which will grant the attackers to have the initial access and information disclosure on the server. This vulnerability is fixed in 1.4.8.

Key dates

02Disclosure timeline

April 9, 2025 CVE published
April 9, 2025 Record updated

Related vulnerabilities

04Related CVE