Target: bentoml/BentoML
File: src/bentoml/_internal/utils/filesystem.py lines 73-75
Type: CWE-59 — Improper Link Resolution Before File Access
CVSS: 8.1 (AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H)
Affected version: commit dd83682 (latest main, Feb 2026)
Bounty program: huntr.com OSV
poc_symlink.tar
Malicious tar: symlink escape → /tmp + file… See the full description on the dataset page:
https://huggingface.co/datasets/NOTTIBOI1337/poc-bentoml-symlink-path-traversal.