VYPR

Mlflow

by Mlflow

pypi: mlflow

Source repositories

CVEs (84)

  • CVE-2023-6974CriDec 20, 2023
    risk 0.57cvss 9.8epss 0.02

    A malicious user could use this issue to access internal HTTP(s) servers and in the worst case (ie: aws instance) it could be abuse to get a remote code execution on the victim machine.

  • CVE-2023-6014CriNov 16, 2023
    risk 0.57cvss 9.8epss 0.01

    An attacker is able to arbitrarily create an account in MLflow bypassing any authentication requirment.

  • CVE-2023-2780CriMay 17, 2023
    risk 0.57cvss 9.8epss 0.06

    Path Traversal: '\..\filename' in GitHub repository mlflow/mlflow prior to 2.3.1.

  • CVE-2026-79721HigSep 8, 2026
    risk 0.56cvss —epss 0.00

    Code execution can occur in versions of the MLflow platform running version 0.0.1 or newer, enabling a maliciously crafted model artifact to execute arbitrary code on an end user's system when loaded by the project.

  • CVE-2026-2611CriMay 19, 2026
    risk 0.55cvss 9.6epss 0.00

    In MLflow version 3.9.0, the MLflow Assistant feature introduced improper origin validation in its /ajax-api endpoints. This vulnerability allows a remote attacker to exploit cross-origin requests from a malicious webpage to interact with the MLflow Assistant running on a…

  • CVE-2024-3573CriApr 16, 2024
    risk 0.54cvss 9.3epss 0.01

    mlflow/mlflow is vulnerable to Local File Inclusion (LFI) due to improper parsing of URIs, allowing attackers to bypass checks and read arbitrary files on the system. The issue arises from the 'is_local_uri' function's failure to properly handle URIs with empty or 'file'…

  • CVE-2024-1560HigApr 16, 2024
    risk 0.53cvss 8.1epss 0.01

    A path traversal vulnerability exists in the mlflow/mlflow repository, specifically within the artifact deletion functionality. Attackers can bypass path validation by exploiting the double decoding process in the `_delete_artifact_mlflow_artifacts` handler and…

  • CVE-2026-2651CriMay 25, 2026
    risk 0.52cvss 9.0epss 0.00

    A vulnerability in MLflow versions <=3.10.1.dev0 allows unauthorized access to multipart upload (MPU) endpoints when the `--serve-artifacts` mode is enabled. The authorization logic does not enforce resource-level permission checks for `/mlflow-artifacts/mpu/*` endpoints,…

  • CVE-2025-15031CriMar 18, 2026
    risk 0.52cvss 9.1epss 0.01

    A vulnerability in MLflow's pyfunc extraction process allows for arbitrary file writes due to improper handling of tar archive entries. Specifically, the use of `tarfile.extractall` without path validation enables crafted tar.gz files containing `..` or absolute paths to escape…

  • CVE-2023-43472HigDec 5, 2023
    risk 0.52cvss 7.5epss 0.37

    An issue in MLFlow versions 2.8.1 and before allows a remote attacker to obtain sensitive information via a crafted request to REST API.

  • CVE-2026-2652HigMay 15, 2026
    risk 0.51cvss 8.6epss 0.21

    A vulnerability in mlflow/mlflow versions 3.9.0 and earlier allows unauthenticated access to certain FastAPI routes when the server is started with authentication enabled (`--app-name basic-auth`) and served via uvicorn (ASGI). The FastAPI permission middleware only enforces…

  • CVE-2025-14287HigMar 16, 2026
    risk 0.50cvss 8.8epss 0.01

    A command injection vulnerability exists in mlflow/mlflow versions before v3.7.0, specifically in the `mlflow/sagemaker/__init__.py` file at lines 161-167. The vulnerability arises from the direct interpolation of user-supplied container image names into shell commands without…

  • CVE-2024-0520HigJun 6, 2024
    risk 0.50cvss 8.8epss 0.02

    A vulnerability in mlflow/mlflow version 8.2.1 allows for remote code execution due to improper neutralization of special elements used in an OS command ('Command Injection') within the `mlflow.data.http_dataset_source.py` module. Specifically, when loading a dataset from a…

  • CVE-2023-6976HigDec 20, 2023
    risk 0.50cvss 8.8epss 0.01

    This vulnerability is capable of writing arbitrary files into arbitrary locations on the remote filesystem in the context of the server process.

  • CVE-2023-6940HigDec 19, 2023
    risk 0.50cvss 8.8epss 0.01

    with only one user interaction(download a malicious config), attackers can gain full command execution on the victim system.

  • CVE-2023-6753HigDec 13, 2023
    risk 0.50cvss 8.8epss 0.01

    Path Traversal in GitHub repository mlflow/mlflow prior to 2.9.2.

  • CVE-2023-6709HigDec 12, 2023
    risk 0.50cvss 8.8epss 0.01

    Improper Neutralization of Special Elements Used in a Template Engine in GitHub repository mlflow/mlflow prior to 2.9.2.

  • CVE-2025-0453HigMar 20, 2025
    risk 0.49cvss 7.5epss 0.11

    In mlflow/mlflow version 2.17.2, the `/graphql` endpoint is vulnerable to a denial of service attack. An attacker can create large batches of queries that repeatedly request all runs from a given experiment. This can tie up all the workers allocated by MLFlow, rendering the…

  • CVE-2024-1594HigApr 16, 2024
    risk 0.49cvss 7.5epss 0.01

    A path traversal vulnerability exists in the mlflow/mlflow repository, specifically within the handling of the `artifact_location` parameter when creating an experiment. Attackers can exploit this vulnerability by using a fragment component `#` in the artifact location URI to…

  • CVE-2024-1593HigApr 16, 2024
    risk 0.49cvss 7.5epss 0.01

    A path traversal vulnerability exists in the mlflow/mlflow repository due to improper handling of URL parameters. By smuggling path traversal sequences using the ';' character in URLs, attackers can manipulate the 'params' portion of the URL to gain unauthorized access to files…

Page 2 of 5