Releases194
Frequency3 days 14 hours
Last Release
Stars12.4K
Run any open-source LLMs, such as DeepSeek and Llama, as OpenAI compatible API endpoint in the cloud.

CVE History

CVEAffectedPublishedCVSS v3CVSS v2
= 0.6.305.3 MEDIUM4.3 MEDIUM

A vulnerability was found in bentoml OpenLLM 0.6.30. This affects the function async_run_command of the file src/openllm/common.py of the component Model Repository Directory Name Handler. Performing a manipulation of the argument cmd results in command injection. Attacking locally is a requirement. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet.