Impact
This vulnerability exists in the async_run_command function of the Model Repository Directory Name Handler in bentoml OpenLLM. By manipulating the cmd argument, a local attacker can inject and execute arbitrary shell commands, effectively gaining control over the system running the service. The weakness corresponds to CWE-74 and CWE-77, indicating improper command validation and potential injection.
Affected Systems
The affected product is bentoml OpenLLM version 0.6.30. No other versions or vendor products are listed as affected.
Risk and Exploitability
The CVSS score of 4.8 indicates moderate severity. The EPSS score of 2% indicates a low probability of exploitation, though a public exploit exists. The vulnerability requires local access to the target and is not listed in the CISA KEV catalog. Because the exploit is publicly disclosed, a local attacker who can reach the service could potentially execute arbitrary commands on the underlying host.
OpenCVE Enrichment