CVE-2026-40610 | BentoML up to 1.4.38 link following (GHSA-mcfx-4vc6-qgxv)
A vulnerability was found in BentoML up to 1.4.38. It has been rated as critical. Affected by this issue is some unknown functionality. The manipulation leads to link following.
This vulnerability is uniquely identified as CVE-2026-40610. Local access is required to approach this attack. No exploit exists.
Upgrading the affected component is advised.