VYPR

Mlflow

by Pypi

CVEs (2)

  • CVE-2026-79721HigSep 8, 2026
    risk 0.56cvss —epss 0.00

    Code execution can occur in versions of the MLflow platform running version 0.0.1 or newer, enabling a maliciously crafted model artifact to execute arbitrary code on an end user's system when loaded by the project.

  • CVE-2026-13484MedJun 28, 2026
    risk 0.33cvss 5.0epss 0.01

    A vulnerability has been found in MLflow up to 4666cffc7912ea606d592fc38d6a75e2935f65e7. The impacted element is an unknown function of the component Experiment-scoped Label Schema CRUD API. Such manipulation leads to missing authorization. It is possible to launch the attack…