{"id":"CVE-2026-15035","summary":"bentoml OpenLLM Model Repository Directory Name common.py async_run_command command injection","details":"A vulnerability was found in bentoml OpenLLM 0.6.30. This affects the function async_run_command of the file src/openllm/common.py of the component Model Repository Directory Name Handler. Performing a manipulation of the argument cmd results in command injection. Attacking locally is a requirement. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet.","aliases":["PYSEC-2026-2089"],"modified":"2026-07-15T01:49:20.134449520Z","published":"2026-07-08T14:00:09.786Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/15xxx/CVE-2026-15035.json","cna_assigner":"VulDB","cwe_ids":["CWE-74","CWE-77"]},"references":[{"type":"WEB","url":"https://github.com/bentoml/OpenLLM/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/15xxx/CVE-2026-15035.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-15035"},{"type":"ADVISORY","url":"https://vuldb.com/cve/CVE-2026-15035"},{"type":"ADVISORY","url":"https://vuldb.com/submit/850895"},{"type":"ADVISORY","url":"https://vuldb.com/vuln/376786"},{"type":"REPORT","url":"https://github.com/bentoml/OpenLLM/issues/1229"},{"type":"REPORT","url":"https://vuldb.com/vuln/376786/cti"},{"type":"FIX","url":"https://github.com/bentoml/OpenLLM/pull/1235"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/bentoml/openllm","events":[{"introduced":"f96ea77c4536efce6d1d39ebbe2da53ad75ae9e5"},{"last_affected":"f96ea77c4536efce6d1d39ebbe2da53ad75ae9e5"}],"database_specific":{"source":["AFFECTED_FIELD","CPE_STRING"],"cpe":"cpe:2.3:a:bentoml:openllm:0.6.30:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0.6.30"},{"last_affected":"0.6.30"}]}}],"versions":["0.6.30","v0.6.30"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-15035.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"}]}