CVE-2026-15035
Last modified
CVE-2026-15035 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. A vulnerability was found in bentoml OpenLLM 0.6.30. This affects the function async_run_command of the file src/openllm/common.py of the component Model Repository Directory Name Handler. EPSS estimates a 0.62% chance of exploitation in the next 30 days.
Description
A vulnerability was found in bentoml OpenLLM 0.6.30. This affects the function async_run_command of the file src/openllm/common.py of the component Model Repository Directory Name Handler. Performing a manipulation of the argument cmd results in command injection. Attacking locally is a requirement. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Bentoml | Openllm | 0.6.30 |
References
- https://github.com/bentoml/OpenLLM/issues/1229Exploit, Patch, Third Party Advisory
- https://github.com/bentoml/OpenLLM/pull/1235Exploit, Patch
- https://vuldb.com/cve/CVE-2026-15035Third Party Advisory, VDB Entry
- https://vuldb.com/submit/850895Exploit, Third Party Advisory, VDB Entry
- https://vuldb.com/vuln/376786Third Party Advisory, VDB Entry
- https://vuldb.com/vuln/376786/ctiPermissions Required
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-15035?
How severe is CVE-2026-15035?
How do I fix CVE-2026-15035?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-15029Untrusted Pointer Dereference in ASUS System Control Interfa…8.4
- CVE-2026-1503The login_register plugin for WordPress is vulnerable to Cro…4.3
- CVE-2026-15030Out-of-bounds Read in ASUS System Control Interface v3, ASUS…5.6
- CVE-2026-15032The Comments WordPress plugin before 7.6.60 does not proper…6.1
- CVE-2026-15033A flaw has been found in christopherthielen check-peer-depen…6.3
- CVE-2026-15034A vulnerability has been found in flask-dashboard Flask-Moni…4.3
- CVE-2026-15036A vulnerability was determined in Harness up to 2.28.2. This…4.3
- CVE-2026-15037Improper output neutralization (XML injection) in QDom comme…2.9
- CVE-2026-15038The InfiniteWP Client WordPress plugin before 1.13.6 does no…9.8
- CVE-2026-15039The giftware WordPress plugin before 4.2.10 does not validat…9.8
- CVE-2026-1504Inappropriate implementation in Background Fetch API in Goog…6.5
- CVE-2026-15041A flaw was found in 389 Directory Server. The PBKDF2-SHA256 …3.7
Are you affected by CVE-2026-15035?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
