VYPR

Mlflow

by Mlflow

pypi: mlflow

Source repositories

CVEs (86)

  • CVE-2026-64849CriKEVAug 17, 2026
    risk 0.66cvss 9.3epss 0.10

    MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. Prior to 3.15.0, the unauthenticated POST /api/2.0/mlflow/webhooks/{id}/test endpoint calls _validate_webhook_url() in mlflow/utils/validation.py only for the…

  • CVE-2026-0545CriApr 3, 2026
    risk 0.64cvss 9.8epss 0.04

    In mlflow/mlflow, the FastAPI job endpoints under `/ajax-api/3.0/jobs/*` are not protected by authentication or authorization when the `basic-auth` app is enabled. This vulnerability affects the latest version of the repository. If job execution is enabled…

  • CVE-2023-3765CriJul 19, 2023
    risk 0.63cvss 10.0epss 0.68

    Absolute Path Traversal in GitHub repository mlflow/mlflow prior to 2.5.0.

  • CVE-2023-6018CriNov 16, 2023
    risk 0.61cvss 9.8epss 0.48

    An attacker can overwrite any file on the server hosting MLflow without any authentication.

  • CVE-2025-11201CriOct 29, 2025
    risk 0.59cvss 9.8epss 0.27

    MLflow Tracking Server Model Creation Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of MLflow Tracking Server. Authentication is not required to exploit this vulnerability. …

  • CVE-2023-1177CriMar 24, 2023
    risk 0.59cvss 9.3epss 0.70

    Path Traversal: '\..\filename' in GitHub repository mlflow/mlflow prior to 2.2.1.

  • CVE-2025-15379CriMar 30, 2026
    risk 0.58cvss 10.0epss 0.02

    A command injection vulnerability exists in MLflow's model serving container initialization code, specifically in the `_install_model_dependencies_to_env()` function. When deploying a model with `env_manager=LOCAL`, MLflow reads dependency specifications from the model…

  • CVE-2025-15036CriMar 30, 2026
    risk 0.58cvss 10.0epss 0.01

    A path traversal vulnerability exists in the `extract_archive_to_dir` function within the `mlflow/pyfunc/dbconnect_artifact_cache.py` file of the mlflow/mlflow repository. This vulnerability, present in versions before v3.7.0, arises due to the lack of validation of tar member…

  • CVE-2026-96804HigSep 23, 2026
    risk 0.57cvss 8.8epss 0.00

    MLflow's statsmodel flavor, versions 2.1.0 to 3.14.0, omits the MLFLOW_ALLOW_PICKLE_DESERIALIZATION=False security control entirely in _load_model(), which allows a remote attacker to execute arbitrary code via a crafted MLmodel artifact.

  • CVE-2026-96775HigSep 23, 2026
    risk 0.57cvss 8.8epss 0.00

    MLflow's dspy flavor, versions >= 2.0, applies the MLFLOW_ALLOW_PICKLE_DESERIALIZATION=False security control only when the model_path ends in .pkl, which allows a remote attacker to execute arbitrary code via a crafted MLmodel artifact.

  • CVE-2025-11200CriOct 29, 2025
    risk 0.57cvss 9.8epss 0.01

    MLflow Weak Password Requirements Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of MLflow. Authentication is not required to exploit this vulnerability. The specific flaw exists within the…

  • CVE-2024-37061HigJun 4, 2024
    risk 0.57cvss 8.8epss 0.01

    Remote Code Execution can occur in versions of the MLflow platform running version 1.11.0 or newer, enabling a maliciously crafted MLproject to execute arbitrary code on an end user’s system when run.

  • CVE-2024-37060HigJun 4, 2024
    risk 0.57cvss 8.8epss 0.01

    Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.27.0 or newer, enabling a maliciously crafted Recipe to execute arbitrary code on an end user’s system when run.

  • CVE-2024-37059HigJun 4, 2024
    risk 0.57cvss 8.8epss 0.01

    Deserialization of untrusted data can occur in versions of the MLflow platform running version 0.5.0 or newer, enabling a maliciously uploaded PyTorch model to run arbitrary code on an end user’s system when interacted with.

  • CVE-2024-37058HigJun 4, 2024
    risk 0.57cvss 8.8epss 0.01

    Deserialization of untrusted data can occur in versions of the MLflow platform running version 2.5.0 or newer, enabling a maliciously uploaded Langchain AgentExecutor model to run arbitrary code on an end user’s system when interacted with.

  • CVE-2024-37057HigJun 4, 2024
    risk 0.57cvss 8.8epss 0.01

    Deserialization of untrusted data can occur in versions of the MLflow platform running version 2.0.0rc0 or newer, enabling a maliciously uploaded Tensorflow model to run arbitrary code on an end user’s system when interacted with.

  • CVE-2024-37056HigJun 4, 2024
    risk 0.57cvss 8.8epss 0.01

    Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.23.0 or newer, enabling a maliciously uploaded LightGBM scikit-learn model to run arbitrary code on an end user’s system when interacted with.

  • CVE-2024-37055HigJun 4, 2024
    risk 0.57cvss 8.8epss 0.01

    Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.24.0 or newer, enabling a maliciously uploaded pmdarima model to run arbitrary code on an end user’s system when interacted with.

  • CVE-2024-37054HigJun 4, 2024
    risk 0.57cvss 8.8epss 0.01

    Deserialization of untrusted data can occur in versions of the MLflow platform running version 0.9.0 or newer, enabling a maliciously uploaded PyFunc model to run arbitrary code on an end user’s system when interacted with.

  • CVE-2024-37053HigJun 4, 2024
    risk 0.57cvss 8.8epss 0.01

    Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.1.0 or newer, enabling a maliciously uploaded scikit-learn model to run arbitrary code on an end user’s system when interacted with.

Page 1 of 5