# RCA Report - GHSA-33xw-247w-6hmc (CVE-2025-27520)

Summary:
- Root Cause: In BentoML <=1.4.2, application/vnd.bentoml+pickle requests were deserialized with pickle.loads when payload.metadata lacked "buffer-lengths" in serde.deserialize_value, allowing execution of attacker-controlled pickle opcodes from HTTP requests.
- Impact: Remote code execution by unauthenticated clients.

Evidence (vulnerable 1.4.2):
- Exploit sent with Content-Type: application/vnd.bentoml+pickle to /summarize.
- Server executed shell commands to append markers to logs/rce_proof.txt.
- Repro script logs show markers present:
  - RCE_ATTEMPT_1_...
  - RCE_ATTEMPT_2_...
  - RCE_ATTEMPT_3_...

Patched verification (latest 1.4.30):
- application/vnd.bentoml+pickle is rejected with 415 ("not allowed in main server").
- Case/param variations return 400/415 and do not execute payloads.
- logs/rce_proof_patched.txt remains empty.

Files:
- Script: bundle/reproduction_steps.sh
- Logs: bundle/logs/*
- Patch analysis: repro/patch_analysis.md
