CVE-2026-24123 | BentoML up to 1.4.33 bentofile.yaml path traversal (GHSA-6r62-w2q3-48hf)
A vulnerability identified as critical has been detected in BentoML up to 1.4.33. This affects an unknown part of the file bentofile.yaml. This manipulation of the argument description/docker.setup_script/docker.dockerfile_template/conda.environment_yml causes path traversal.
This vulnerability appears as CVE-2026-24123. The attack may be initiated remotely. There is no available exploit.
You should upgrade the affected component.