CVE-2026-27905 | BentoML up to 1.4.35 Bento safe_extract_tarfile link following (GHSA-m6w7-qv66-g3mf / Nessus ID 300821)
A vulnerability categorized as critical has been discovered in BentoML up to 1.4.35. Affected is the function safe_extract_tarfile of the component Bento Handler. Executing a manipulation can lead to link following.
This vulnerability is tracked as CVE-2026-27905. The attack is restricted to local execution. No exploit exists.
It is advisable to upgrade the affected component.