High severity7.1NVD Advisory· Published Mar 20, 2025· Updated Jun 17, 2026
CVE-2025-1473
CVE-2025-1473
Description
A Cross-Site Request Forgery (CSRF) vulnerability exists in the Signup feature of mlflow/mlflow versions 2.17.0 to 2.20.1. This vulnerability allows an attacker to create a new account, which may be used to perform unauthorized actions on behalf of the malicious user.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
mlflowPyPI | >= 2.17.0, < 2.20.3 | 2.20.3 |
Affected products
4- ghsa-coords2 versions
>= 2.17.0, < 2.20.3+ 1 more
- (no CPE)range: >= 2.17.0, < 2.20.3
- (no CPE)range: >= 2.17.0, < 2.20.1
Patches
Vulnerability mechanics
References
4- github.com/mlflow/mlflow/commit/ecfa61cb43d3303589f3b5834fd95991c9706628nvdPatchWEB
- huntr.com/bounties/43dc50b6-7d1e-41b9-9f97-f28809df1d45nvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-969w-gqqr-g6j3ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2025-1473ghsaADVISORY
News mentions
0No linked articles in our index yet.