VYPR

Mlflow

by Mlflow

pypi: mlflow

Source repositories

CVEs (84)

  • CVE-2024-1558HigApr 16, 2024
    risk 0.49cvss 7.5epss 0.01

    A path traversal vulnerability exists in the `_create_model_version()` function within `server/handlers.py` of the mlflow/mlflow repository, due to improper validation of the `source` parameter. Attackers can exploit this vulnerability by crafting a `source` parameter that…

  • CVE-2024-1483HigApr 16, 2024
    risk 0.49cvss 7.5epss 0.03

    A path traversal vulnerability exists in mlflow/mlflow version 2.9.2, allowing attackers to access arbitrary files on the server. By crafting a series of HTTP POST requests with specially crafted 'artifact_location' and 'source' parameters, using a local URI with '#' instead of…

  • CVE-2023-6909HigDec 18, 2023
    risk 0.49cvss 7.5epss 0.90

    Path Traversal: '\..\filename' in GitHub repository mlflow/mlflow prior to 2.9.2.

  • CVE-2026-8147HigJul 2, 2026
    risk 0.46cvss 8.1epss 0.01

    In MLflow versions prior to 3.14.0, when running with authentication enabled, the trace API endpoints lack proper authorization validators. This allows any authenticated user to bypass experiment-level authorization controls on all trace operations, including reading, deleting,…

  • CVE-2025-15381HigMar 27, 2026
    risk 0.46cvss 7.1epss 0.00

    In the latest version of mlflow/mlflow, when the `basic-auth` app is enabled, tracing and assessment endpoints are not protected by permission validators. This allows any authenticated user, including those with `NO_PERMISSIONS` on the experiment, to read trace information and…

  • CVE-2025-14279HigJan 12, 2026
    risk 0.46cvss 8.1epss 0.00

    MLFlow versions up to and including 3.4.0 are vulnerable to DNS rebinding attacks due to a lack of Origin header validation in the MLFlow REST server. This vulnerability allows malicious websites to bypass Same-Origin Policy protections and execute unauthorized calls against…

  • CVE-2023-6831HigDec 15, 2023
    risk 0.46cvss 8.1epss 0.03

    Path Traversal: '\..\filename' in GitHub repository mlflow/mlflow prior to 2.9.2.

  • CVE-2024-3848HigMay 16, 2024
    risk 0.45cvss 7.5epss 0.43

    A path traversal vulnerability exists in mlflow/mlflow version 2.11.0, identified as a bypass for the previously addressed CVE-2023-6909. The vulnerability arises from the application's handling of artifact URLs, where a '#' character can be used to insert a path into the…

  • CVE-2026-4137HigMay 18, 2026
    risk 0.44cvss 7.8epss 0.00

    In mlflow/mlflow versions prior to 3.11.0, the `get_or_create_nfs_tmp_dir()` function in `mlflow/utils/file_utils.py` creates temporary directories with world-writable permissions (0o777), and the `_create_model_downloading_tmp_dir()` function in `mlflow/pyfunc/__init__.py`…

  • CVE-2026-0596HigMar 31, 2026
    risk 0.44cvss 7.8epss 0.01

    A command injection vulnerability exists in mlflow/mlflow when serving a model with `enable_mlserver=True`. The `model_uri` is embedded directly into a shell command executed via `bash -c` without proper sanitization. If the `model_uri` contains shell metacharacters, such as…

  • CVE-2023-4033HigAug 1, 2023
    risk 0.44cvss 7.8epss 0.01

    OS Command Injection in GitHub repository mlflow/mlflow prior to 2.6.0.

  • CVE-2026-4035HigJun 3, 2026
    risk 0.43cvss 7.7epss 0.01

    A vulnerability in mlflow/mlflow versions prior to 3.11.0 allows for the resolution of environment variables in AI Gateway secrets, which can be exploited to exfiltrate sensitive server-side environment credentials to an attacker-controlled endpoint. This issue arises because…

  • CVE-2024-2928HigJun 6, 2024
    risk 0.43cvss 7.5epss 0.22

    A Local File Inclusion (LFI) vulnerability was identified in mlflow/mlflow, specifically in version 2.9.2, which was fixed in version 2.11.3. This vulnerability arises from the application's failure to properly validate URI fragments for directory traversal sequences such as…

  • CVE-2026-2614HigMay 11, 2026
    risk 0.42cvss 7.5epss 0.04

    A vulnerability in the `_create_model_version()` handler of `mlflow/server/handlers.py` in mlflow/mlflow versions 3.9.0 and earlier allows an unauthenticated remote attacker to read arbitrary files from the server's filesystem. The issue arises when a `CreateModelVersion`…

  • CVE-2024-8859HigMar 20, 2025
    risk 0.42cvss 7.5epss 0.03

    A path traversal vulnerability exists in mlflow/mlflow version 2.15.1. When users configure and use the dbfs service, concatenating the URL directly into the file protocol results in an arbitrary file read vulnerability. This issue occurs because only the path part of the URL is…

  • CVE-2024-27133HigFeb 23, 2024
    risk 0.42cvss 7.5epss 0.01

    Insufficient sanitization in MLflow leads to XSS when running a recipe that uses an untrusted dataset. This issue leads to a client-side RCE when running the recipe in Jupyter Notebook. The vulnerability stems from lack of sanitization over dataset table fields.

  • CVE-2024-27132HigFeb 23, 2024
    risk 0.42cvss 7.5epss 0.01

    Insufficient sanitization in MLflow leads to XSS when running an untrusted recipe. This issue leads to a client-side RCE when running an untrusted recipe in Jupyter Notebook. The vulnerability stems from lack of sanitization over template variables.

  • CVE-2023-6977HigDec 20, 2023
    risk 0.42cvss 7.5epss 0.04

    This vulnerability enables malicious users to read sensitive files on the server.

  • CVE-2023-6015HigNov 16, 2023
    risk 0.42cvss 7.5epss 0.04

    MLflow allowed arbitrary files to be PUT onto the server.

  • CVE-2023-30172HigMay 11, 2023
    risk 0.42cvss 7.5epss 0.01

    A directory traversal vulnerability in the /get-artifact API method of the mlflow platform up to v2.0.1 allows attackers to read arbitrary files on the server via the path parameter.