VYPR

Mlflow

by Mlflow

pypi: mlflow

Source repositories

CVEs (84)

  • CVE-2023-2356HigApr 28, 2023
    risk 0.42cvss 7.5epss 0.04

    Relative Path Traversal in GitHub repository mlflow/mlflow prior to 2.3.1.

  • CVE-2022-0736HigFeb 23, 2022
    risk 0.42cvss 7.5epss 0.02

    Insecure Temporary File in GitHub repository mlflow/mlflow prior to 1.23.1.

  • CVE-2026-2635HigFeb 20, 2026
    risk 0.41cvss 7.3epss 0.01

    MLflow Use of Default Password Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of MLflow. Authentication is not required to exploit this vulnerability. The specific flaw exists within the…

  • CVE-2026-2033HigFeb 20, 2026
    risk 0.41cvss 7.3epss 0.02

    MLflow Tracking Server Artifact Handler Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of MLflow Tracking Server. Authentication is not required to exploit this…

  • CVE-2026-69148HigAug 17, 2026
    risk 0.39cvss 7.1epss 0.00

    MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. Prior to 3.15.0, CreateModelVersion accepts a run_id or model_id after _validate_source_run() or _validate_source_model() in mlflow/server/handlers.py verifies only…

  • CVE-2026-71211HigAug 5, 2026
    risk 0.39cvss 7.1epss 0.00

    MLflow's AI Gateway accepts an auth_config.api_base value when creating a gateway secret (mlflow/server/handlers.py, _create_gateway_secret) with no validation of scheme, host, or IP range; the value is stored verbatim. The gateway proxy endpoint (mlflow/server/gateway_api.py,…

  • CVE-2026-2393HigMay 11, 2026
    risk 0.39cvss 7.1epss 0.00

    A Server-Side Request Forgery (SSRF) vulnerability exists in MLflow versions prior to 3.9.0. The `_create_webhook()` function in `mlflow/server/handlers.py` accepts a user-controlled `url` parameter without validation, and the `_send_webhook_request()` function in…

  • CVE-2025-10279HigFeb 2, 2026
    risk 0.39cvss 7.0epss 0.00

    In mlflow version 2.20.3, the temporary directory used for creating Python virtual environments is assigned insecure world-writable permissions (0o777). This vulnerability allows an attacker with write access to the `/tmp` directory to exploit a race condition and overwrite…

  • CVE-2025-1473HigMar 20, 2025
    risk 0.39cvss 7.1epss 0.00

    A Cross-Site Request Forgery (CSRF) vulnerability exists in the Signup feature of mlflow/mlflow versions 2.17.0 to 2.20.1. This vulnerability allows an attacker to create a new account, which may be used to perform unauthorized actions on behalf of the malicious user.

  • CVE-2024-27134HigNov 25, 2024
    risk 0.39cvss 7.0epss 0.00

    Excessive directory permissions in MLflow leads to local privilege escalation when using spark_udf. This behavior can be exploited by a local attacker to gain elevated permissions by using a ToCToU attack. The issue is only relevant when the spark_udf() MLflow API is called.

  • CVE-2026-69146MedAug 17, 2026
    risk 0.35cvss 6.5epss 0.00

    MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. From 3.13.0 until 3.15.0, LogInputs is absent from BEFORE_REQUEST_HANDLERS in the mlflow/server/auth package, allowing any authenticated user to call POST…

  • CVE-2026-3198MedJun 2, 2026
    risk 0.35cvss 6.5epss 0.00

    MLflow 3.9.0 with basic-auth (`--app-name basic-auth`) fails to enforce authorization checks for multiple Gateway API 'list' endpoints. Specifically, the `BEFORE_REQUEST_HANDLERS` dictionary in `mlflow/server/auth/__init__.py` does not include entries for…

  • CVE-2026-2734MedMay 21, 2026
    risk 0.35cvss 6.5epss 0.00

    In mlflow/mlflow versions up to 3.9.0, the `SearchModelVersions` REST API endpoint and the `mlflowSearchModelVersions` GraphQL query lack proper per-model authorization checks when basic authentication is enabled. This allows any authenticated user to enumerate all model…

  • CVE-2024-3099MedJun 6, 2024
    risk 0.35cvss 5.4epss 0.00

    A vulnerability in mlflow/mlflow version 2.11.1 allows attackers to create multiple models with the same name by exploiting URL encoding. This flaw can lead to Denial of Service (DoS) as an authenticated user might not be able to use the intended model, as it will open a…

  • CVE-2024-6838MedMar 20, 2025
    risk 0.34cvss 5.3epss 0.01

    In mlflow/mlflow version v2.13.2, a vulnerability exists that allows the creation or renaming of an experiment with a large number of integers in its name due to the lack of a limit on the experiment name. This can cause the MLflow UI panel to become unresponsive, leading to a…

  • CVE-2026-13484MedJun 28, 2026
    risk 0.33cvss 5.0epss 0.01

    A vulnerability has been found in MLflow up to 4666cffc7912ea606d592fc38d6a75e2935f65e7. The impacted element is an unknown function of the component Experiment-scoped Label Schema CRUD API. Such manipulation leads to missing authorization. It is possible to launch the attack…

  • CVE-2023-6568MedDec 7, 2023
    risk 0.33cvss 6.1epss 0.02

    A reflected Cross-Site Scripting (XSS) vulnerability exists in the mlflow/mlflow repository, specifically within the handling of the Content-Type header in POST requests. An attacker can inject malicious JavaScript code into the Content-Type header, which is then improperly…

  • CVE-2025-52967MedJun 23, 2025
    risk 0.31cvss 5.8epss 0.00

    gateway_proxy_handler in MLflow before 3.1.0 lacks gateway_path validation.

  • CVE-2025-1474MedMar 20, 2025
    risk 0.29cvss 5.5epss 0.00

    In mlflow/mlflow version 2.18, an admin is able to create a new user account without setting a password. This vulnerability could lead to security risks, as accounts without passwords may be susceptible to unauthorized access. Additionally, this issue violates best practices for…

  • CVE-2026-33865MedApr 7, 2026
    risk 0.28cvss 5.4epss 0.00

    MLflow is vulnerable to Stored Cross-Site Scripting (XSS) caused by unsafe parsing of YAML-based MLmodel artifacts in its web interface. An authenticated attacker can upload a malicious MLmodel file containing a payload that executes when another user views the artifact in the…

Page 4 of 5