📦 Mlflow

by Lfprojects

🔍 What is Mlflow?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-11200

CRITICAL CVSS 9.8 Oct 29, 2025

This vulnerability allows remote attackers to bypass authentication in MLflow installations due to weak password requirements. Attackers can gain unauthorized access without credentials. All MLflow de...

CVE-2024-3573

CRITICAL CVSS 9.3 Apr 16, 2024

This vulnerability in MLflow allows attackers to perform Local File Inclusion (LFI) by exploiting improper URI parsing in the 'is_local_uri' function. Attackers can craft malicious model versions with...

CVE-2023-6974

CRITICAL CVSS 9.8 Dec 20, 2023

This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in MLflow that allows attackers to make unauthorized requests to internal HTTP(s) servers. Attackers could potentially access sens...

CVE-2023-6014

CRITICAL CVSS 9.8 Nov 16, 2023

This vulnerability allows unauthenticated attackers to create arbitrary user accounts in MLflow deployments, bypassing all authentication requirements. Any organization using MLflow for machine learni...

CVE-2023-3765

CRITICAL CVSS 10.0 Jul 19, 2023

This vulnerability allows attackers to perform absolute path traversal attacks in MLflow deployments prior to version 2.5.0. Attackers can potentially access arbitrary files on the server filesystem b...

CVE-2023-2780

CRITICAL CVSS 9.8 May 17, 2023

This CVE describes a path traversal vulnerability in MLflow where attackers can use '\..\filename' sequences to access files outside intended directories. It affects MLflow deployments prior to versio...

CVE-2025-0453

HIGH CVSS 7.5 Mar 20, 2025

This vulnerability in MLflow's GraphQL endpoint allows attackers to cause denial of service by sending specially crafted queries that consume excessive server resources. Attackers can tie up all worke...

CVE-2025-1473

HIGH CVSS 7.1 Mar 20, 2025

A Cross-Site Request Forgery vulnerability in MLflow's signup feature allows attackers to create unauthorized accounts by tricking authenticated users into submitting malicious requests. This affects ...

CVE-2024-8859

HIGH CVSS 7.5 Mar 20, 2025

A path traversal vulnerability in MLflow 2.15.1 allows attackers to read arbitrary files when the DBFS service is configured and mounted locally. This occurs because URL query parameters aren't proper...

CVE-2024-27134

HIGH CVSS 7.0 Nov 25, 2024

This vulnerability allows local attackers to escalate privileges on systems running MLflow when the spark_udf() API is called. Attackers can exploit improper directory permissions using a Time-of-Chec...

CVE-2024-0520

HIGH CVSS 8.8 Jun 6, 2024

This CVE allows remote code execution in MLflow versions before 2.9.0 due to command injection vulnerability. Attackers can manipulate file paths when loading datasets from HTTP sources, leading to ar...

CVE-2024-37058

HIGH CVSS 8.8 Jun 4, 2024

This vulnerability in MLflow allows remote code execution when users interact with maliciously uploaded Langchain AgentExecutor models. Attackers can exploit deserialization flaws to run arbitrary cod...

CVE-2024-37060

HIGH CVSS 8.8 Jun 4, 2024

This vulnerability in MLflow allows remote code execution when deserializing untrusted data from malicious Recipes. It affects MLflow versions 1.27.0 and newer, putting users who run untrusted MLflow ...

CVE-2024-37054

HIGH CVSS 8.8 Jun 4, 2024

This vulnerability allows remote code execution through malicious PyFunc models in MLflow. Attackers can upload specially crafted models that execute arbitrary code when users interact with them. Orga...

CVE-2024-37056

HIGH CVSS 8.8 Jun 4, 2024

This vulnerability allows remote code execution through malicious ML models in MLflow. Attackers can upload specially crafted LightGBM scikit-learn models that execute arbitrary code when loaded. Orga...

CVE-2024-37052

HIGH CVSS 8.8 Jun 4, 2024

This vulnerability allows remote code execution through malicious ML models in MLflow. Attackers can upload specially crafted scikit-learn models that execute arbitrary code when loaded. Organizations...

CVE-2024-1593

HIGH CVSS 7.5 Apr 16, 2024

A path traversal vulnerability in MLflow allows attackers to use ';' characters in URL parameters to access unauthorized files or directories. This affects MLflow deployments where the vulnerable code...

CVE-2024-1558

HIGH CVSS 7.5 Apr 16, 2024

This path traversal vulnerability in MLflow allows attackers to read arbitrary files on the server by exploiting improper validation of the source parameter in model version creation. It affects MLflo...

CVE-2024-27133

HIGH CVSS 7.5 Feb 23, 2024

CVE-2024-27133 is a cross-site scripting (XSS) vulnerability in MLflow that occurs when running recipes with untrusted datasets. Insufficient sanitization of dataset table fields allows attackers to i...

CVE-2023-6976

HIGH CVSS 8.8 Dec 20, 2023

This vulnerability in MLflow allows attackers to write arbitrary files to arbitrary locations on the server filesystem, potentially leading to remote code execution. It affects MLflow deployments with...

CVE-2023-6940

HIGH CVSS 8.8 Dec 19, 2023

CVE-2023-6940 is a command injection vulnerability in MLflow that allows attackers to execute arbitrary commands on the victim system by tricking users into downloading a malicious configuration file....

CVE-2023-6909

HIGH CVSS 7.5 Dec 18, 2023

This path traversal vulnerability in MLflow allows attackers to access arbitrary files on the server by using '\..\filename' sequences in requests. It affects MLflow deployments prior to version 2.9.2...

CVE-2023-6753

HIGH CVSS 8.8 Dec 13, 2023

This path traversal vulnerability in MLflow allows attackers to read arbitrary files on the server by manipulating file paths in requests. It affects all MLflow deployments running versions prior to 2...

CVE-2023-43472

HIGH CVSS 7.5 Dec 5, 2023

This vulnerability in MLFlow allows remote attackers to access sensitive information through crafted REST API requests. It affects MLFlow deployments with exposed REST APIs, potentially exposing model...

CVE-2023-6015

HIGH CVSS 7.5 Nov 16, 2023

CVE-2023-6015 is a path traversal vulnerability in MLflow that allows attackers to upload arbitrary files to any location on the server's filesystem. This affects MLflow deployments with the artifact ...

CVE-2023-4033

HIGH CVSS 7.8 Aug 1, 2023

This CVE describes an OS command injection vulnerability in MLflow versions prior to 2.6.0. Attackers can execute arbitrary operating system commands on the server by injecting malicious input into vu...

CVE-2025-1474

MEDIUM CVSS 5.5 Mar 20, 2025

In MLflow versions 2.18, administrators can create user accounts without setting passwords, violating secure account management practices. This vulnerability could allow unauthorized access to these a...