VYPR

Mlflow

by Mlflow

pypi: mlflow

Source repositories

CVEs (84)

  • CVE-2024-4263MedMay 16, 2024
    risk 0.28cvss 5.4epss 0.00

    A broken access control vulnerability exists in mlflow/mlflow versions before 2.10.1, where low privilege users with only EDIT permissions on an experiment can delete any artifacts. This issue arises due to the lack of proper validation for DELETE requests by users with EDIT…

  • CVE-2026-33866MedApr 7, 2026
    risk 0.21cvss 4.3epss 0.00

    MLflow is vulnerable to an authorization bypass affecting the AJAX endpoint used to download saved model artifacts. Due to missing access‑control validation, a user without permissions to a given experiment can directly query this endpoint and retrieve model artifacts they are…

  • CVE-2026-10803LowJun 4, 2026
    risk 0.16cvss 3.6epss 0.00

    A flaw has been found in MLflow up to 3.10.0. This issue affects the function mlflow.data.digest_utils of the file mlflow/data/digest_utils.py of the component Dataset Digest Computation. This manipulation causes use of weak hash. It is possible to launch the attack on the local…

  • CVE-2023-1176LowMar 24, 2023
    risk 0.14cvss 3.3epss 0.01

    Absolute Path Traversal in GitHub repository mlflow/mlflow prior to 2.2.2.

Page 5 of 5