CVE-2026-15035: Bentoml Openllm

High severity, CVSS 7.8. EPSS: 2.2% chance of exploitation in the next 30 days.

A vulnerability was found in bentoml OpenLLM 0.6.30. This affects the function async_run_command of the file src/openllm/common.py of the component Model Repository Directory Name Handler. Performing a manipulation of the argument cmd results in command injection. Attacking locally is a requirement. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet.

Affected products

  • Bentoml Openllm: version 0.6.30 only

Published 2026-07-08. Last modified 2026-07-09.