CVE-2025-32375 is a critical insecure deserialization vulnerability in BentoML’s runner server affecting versions 1.0.0a1 through 1.4.7. The issue arises from deserialization of untrusted HTTP request data using Python’s pickle module in the runner server code path, including the _deserialize_single_param function in runner_app.py. By sending a crafted POST request with specific headers such as args-number: 1, Payload-Container: NdarrayContainer, and Payload-Meta: {"format": "default"}, along with a malicious pickled object in the request body, an unauthenticated attacker can trigger arbitrary code execution during deserialization. The provided context indicates proof-of-concept exploitation via a pickle payload abusing Python’s reduce method to invoke os.system.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
4 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a minimal proof-of-concept exploit consisting of a short README linking to a BentoML security advisory and a single Python script, exploit.py. The script uses the requests and pickle modules to send a crafted HTTP POST request to a BentoML service at port 3000. It sets BentoML-specific headers, most notably Content-Type 'application/vnd.bentoml.pickled', indicating the target is expected to deserialize a Python pickle payload. The exploit capability is remote code execution through unsafe pickle deserialization. A custom class P overrides __reduce__ so that deserialization invokes os.system with an attacker-supplied shell command. That command attempts to establish shell access using bash, a FIFO at /tmp/f, and netcat to a callback host on TCP/4444, while also wrapping the output in a curl POST to an attacker-controlled HTTP endpoint on port 1337. Repository structure is extremely small and purpose-built: README.md only references the upstream advisory, while exploit.py is the sole operational file and clear entry point. There is no argument parsing, target validation, or payload customization logic beyond hardcoded values, so this is best characterized as an operational but basic exploit rather than a framework-integrated or weaponized tool.
This repository is a small self-contained unsafe deserialization exploit lab/CTF-style PoC. It contains a vulnerable Flask application (app.py), a Python exploit client (exploit.py), and a large HTML/JavaScript dashboard template (templates/index.html). The core vulnerability is in app.py: the POST /api/v1/predict endpoint accepts JSON, extracts model_input, base64-decodes it, and passes the result directly to pickle.loads(). Because pickle deserialization is attacker-controlled, arbitrary Python code can execute on the server during object reconstruction. The app listens only on 127.0.0.1:5000 in debug mode, suggesting a local demo or training environment rather than an internet-facing implant. The exploit in exploit.py defines a class with a malicious __reduce__ method returning os.system with the argument whoami. The script serializes this object with pickle.dumps(), base64-encodes it, and sends it as JSON to http://127.0.0.1:5000/api/v1/predict using requests. Successful exploitation yields command execution in the Flask server context while the API may still return a benign-looking success message. Repository structure and purpose: - app.py: vulnerable Flask ML-themed API service and web UI router. - exploit.py: proof-of-concept exploit that weaponizes pickle deserialization for command execution. - templates/index.html: themed dashboard/front-end that simulates an AI model serving platform and includes client-side JavaScript for sending arbitrary POST requests. Overall, this is a real exploit PoC for Python pickle-based RCE against a deliberately vulnerable local web API. It is not a scanner or detection script. The payload is basic and hardcoded, so maturity is best classified as OPERATIONAL rather than WEAPONIZED.
This repository provides a proof-of-concept exploit for CVE-2025-32375, targeting BentoML version 1.4.7. The structure includes Docker and docker-compose files to set up a vulnerable BentoML service, as well as Python scripts for model creation and service definition. The main exploit is in 'exploit.py', which crafts a malicious pickle payload that, when deserialized by the vulnerable service, executes an OS command ('id') and sends the output to an attacker-controlled HTTP endpoint (http://host.docker.internal:1337). The exploit demonstrates remote code execution via unsafe deserialization. The repository is well-structured for testing and demonstration, with clear setup instructions and all necessary components to reproduce the vulnerability in a containerized environment.
This repository contains a single Metasploit module targeting CVE-2025-32375, a remote code execution vulnerability in BentoML's runner server prior to version 1.4.8. The exploit leverages insecure deserialization by sending a specially crafted POST request with malicious headers and a pickled payload to the server's root endpoint. The module supports both Python and Linux command payloads, allowing for reverse shells or arbitrary command execution. The module includes a check method to verify the presence and readiness of the BentoML runner server by querying the '/metrics' and '/readyz' endpoints. The exploit is weaponized, as it is part of the Metasploit framework and supports customizable payloads. The repository is structured as a single Ruby file under the Metasploit modules directory, and is intended for use within the Metasploit exploitation framework.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A remote code execution vulnerability affecting the BentoML runner server component; mentioned as part of the vendor's prior security history.
A critical remote code execution vulnerability in the BentoML runner server caused by insecure deserialization of untrusted HTTP request data using Python's pickle module.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.