CVE-2025-27520 is a remote code execution vulnerability in BentoML, a Python library for building online serving systems for AI applications and model inference. According to the provided content, the flaw is caused by insecure deserialization in an unsafe code segment within serde.py. The issue affects BentoML version 1.4.2 and allows an unauthenticated attacker to execute arbitrary code on the server by supplying crafted serialized input that is deserialized unsafely.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
3 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository is a minimal exploit PoC for CVE-2025-27520 targeting BentoML insecure deserialization. It contains two files: a Python exploit script and a short README describing the vulnerability. The main script builds a malicious pickle object by defining a class with a __reduce__ method that resolves to os.system, causing arbitrary shell command execution when deserialized by the target. The command creates a FIFO at /tmp/f and launches a netcat-based reverse shell to an attacker-supplied host and port. The exploit then sends the serialized payload in an HTTP POST request to the target endpoint /summarize with Content-Type application/vnd.bentoml+pickle. The exploit is straightforward and operational rather than framework-based: it requires command-line arguments for callback and target addressing, performs no vulnerability verification, and assumes the remote BentoML service will deserialize untrusted pickle data unauthenticated. The README states the vulnerable version is BentoML 1.4.2 and that the issue is fixed in 1.4.3.
This repository is an educational lab demonstrating the insecure deserialization vulnerability (CVE-2025-27520) that affected BentoML prior to version 1.4.3. The main application (app.py) is a Flask web server exposing two endpoints: /predict, which is intentionally vulnerable to arbitrary code execution via unsafe unpickling of attacker-supplied base64-encoded pickle payloads, and /flag, which returns the contents of a flag file. The exploit (exploit.sh) generates a malicious pickle payload that, when sent to /predict, causes the server to execute 'cat /opt/flag.txt' and return the flag. The repository includes Dockerfile and entrypoint.sh for containerized setup, and requirements.txt for dependencies. The exploit demonstrates the risk of insecure deserialization in Python web applications and is intended for local, educational use only.
This repository contains a single Metasploit module (modules/exploits/linux/http/bentoml_rce_cve_2025_27520.rb) that exploits an unauthenticated remote code execution (RCE) vulnerability (CVE-2025-27520) in BentoML versions 1.3.4 through 1.4.2. The exploit leverages insecure Python deserialization via a POST request to a vulnerable API endpoint, which is discovered by querying /docs.json on the target server. The module supports both Python and Linux command payloads, allowing for reverse shells or arbitrary command execution. The exploit is fully weaponized, supporting customizable payloads and automatic endpoint discovery, and is intended for use within the Metasploit framework. The only file in the repository is the exploit module itself, written in Ruby.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A remote code execution vulnerability in BentoML caused by insecure deserialization; mentioned as part of the vendor's prior security history.
A previously addressed critical BentoML vulnerability involving insecure deserialization.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.