VYPR
Vendor

Mlflow

Products
19
CVEs
117
Across products
119
Status
Private

Products

19

Recent CVEs

117
View all 117 CVEs →
  • CVE-2026-0545CriApr 3, 2026
    risk 0.64cvss 9.8epss 0.04

    In mlflow/mlflow, the FastAPI job endpoints under `/ajax-api/3.0/jobs/*` are not protected by authentication or authorization when the `basic-auth` app is enabled. This vulnerability affects the latest version of the repository. If job execution is enabled…

  • CVE-2023-23619CriJan 26, 2023
    risk 0.64cvss 9.9epss 0.01

    Modelina is a library for generating data models based on inputs such as AsyncAPI, OpenAPI, or JSON Schema documents. Versions prior to 1.0.0 are vulnerable to Code injection. This issue affects anyone who is using the default presets and/or does not handle the functionality…

  • CVE-2023-3765CriJul 19, 2023
    risk 0.63cvss 10.0epss 0.68

    Absolute Path Traversal in GitHub repository mlflow/mlflow prior to 2.5.0.

  • CVE-2023-6018CriNov 16, 2023
    risk 0.61cvss 9.8epss 0.48

    An attacker can overwrite any file on the server hosting MLflow without any authentication.

  • CVE-2025-68145CriDec 17, 2025
    risk 0.60cvss 9.1epss 0.07

    In mcp-server-git versions prior to 2025.12.17, when the server is started with the --repository flag to restrict operations to a specific repository path, it did not validate that repo_path arguments in subsequent tool calls were actually within that configured path. This could…

  • CVE-2025-11201CriOct 29, 2025
    risk 0.59cvss 9.8epss 0.27

    MLflow Tracking Server Model Creation Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of MLflow Tracking Server. Authentication is not required to exploit this vulnerability. …

  • CVE-2023-1177CriMar 24, 2023
    risk 0.59cvss 9.3epss 0.70

    Path Traversal: '\..\filename' in GitHub repository mlflow/mlflow prior to 2.2.1.

  • CVE-2025-15036CriMar 30, 2026
    risk 0.58cvss 10.0epss 0.01

    A path traversal vulnerability exists in the `extract_archive_to_dir` function within the `mlflow/pyfunc/dbconnect_artifact_cache.py` file of the mlflow/mlflow repository. This vulnerability, present in versions before v3.7.0, arises due to the lack of validation of tar member…

  • CVE-2025-15379CriMar 30, 2026
    risk 0.57cvss 9.8epss 0.02

    A command injection vulnerability exists in MLflow's model serving container initialization code, specifically in the `_install_model_dependencies_to_env()` function. When deploying a model with `env_manager=LOCAL`, MLflow reads dependency specifications from the model…

  • CVE-2025-11200CriOct 29, 2025
    risk 0.57cvss 9.8epss 0.01

    MLflow Weak Password Requirements Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of MLflow. Authentication is not required to exploit this vulnerability. The specific flaw exists within the…

  • CVE-2024-37061HigJun 4, 2024
    risk 0.57cvss 8.8epss 0.01

    Remote Code Execution can occur in versions of the MLflow platform running version 1.11.0 or newer, enabling a maliciously crafted MLproject to execute arbitrary code on an end user’s system when run.

  • CVE-2024-37060HigJun 4, 2024
    risk 0.57cvss 8.8epss 0.01

    Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.27.0 or newer, enabling a maliciously crafted Recipe to execute arbitrary code on an end user’s system when run.

  • CVE-2024-37059HigJun 4, 2024
    risk 0.57cvss 8.8epss 0.01

    Deserialization of untrusted data can occur in versions of the MLflow platform running version 0.5.0 or newer, enabling a maliciously uploaded PyTorch model to run arbitrary code on an end user’s system when interacted with.

  • CVE-2024-37058HigJun 4, 2024
    risk 0.57cvss 8.8epss 0.01

    Deserialization of untrusted data can occur in versions of the MLflow platform running version 2.5.0 or newer, enabling a maliciously uploaded Langchain AgentExecutor model to run arbitrary code on an end user’s system when interacted with.

  • CVE-2024-37057HigJun 4, 2024
    risk 0.57cvss 8.8epss 0.01

    Deserialization of untrusted data can occur in versions of the MLflow platform running version 2.0.0rc0 or newer, enabling a maliciously uploaded Tensorflow model to run arbitrary code on an end user’s system when interacted with.

  • CVE-2024-37056HigJun 4, 2024
    risk 0.57cvss 8.8epss 0.01

    Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.23.0 or newer, enabling a maliciously uploaded LightGBM scikit-learn model to run arbitrary code on an end user’s system when interacted with.

  • CVE-2024-37055HigJun 4, 2024
    risk 0.57cvss 8.8epss 0.01

    Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.24.0 or newer, enabling a maliciously uploaded pmdarima model to run arbitrary code on an end user’s system when interacted with.

  • CVE-2024-37054HigJun 4, 2024
    risk 0.57cvss 8.8epss 0.01

    Deserialization of untrusted data can occur in versions of the MLflow platform running version 0.9.0 or newer, enabling a maliciously uploaded PyFunc model to run arbitrary code on an end user’s system when interacted with.

  • CVE-2024-37053HigJun 4, 2024
    risk 0.57cvss 8.8epss 0.01

    Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.1.0 or newer, enabling a maliciously uploaded scikit-learn model to run arbitrary code on an end user’s system when interacted with.

  • CVE-2024-37052HigJun 4, 2024
    risk 0.57cvss 8.8epss 0.01

    Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.1.0 or newer, enabling a maliciously uploaded scikit-learn model to run arbitrary code on an end user’s system when interacted with.