mlflow
Products: MLflow · mlflow/mlflow
40.6
Score
29
CVEs
1
Active
28
PoC
1
KEV
#68
Rank
Period:
Product:
| CVE ID | Published | CVSS | Exploit | KEV | AC | PR | Auto | Score(hover) | Affected Products | Description |
|---|---|---|---|---|---|---|---|---|---|---|
| CVE-2026-64849 | 2026-08-17 | 9.3v3.1 | ACTIVE | Low | None | YES | 40.6 | MLflow | MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. Prior to 3.15.0, the unauthenticated POST /api/2.0/mlflow/webhooks/{id}/test endpoint calls _validate_webhook_url() in mlflow/utils/validation.py only for the original URL while mlflow/we | |
| CVE-2026-69146 | 2026-08-17 | 6.5v3.1 | POC | — | Low | Low | no | 0.0 | MLflow | MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. From 3.13.0 until 3.15.0, LogInputs is absent from BEFORE_REQUEST_HANDLERS in the mlflow/server/auth package, allowing any authenticated user to call POST /api/2.0/mlflow/runs/log-inputs |
| CVE-2026-69148 | 2026-08-17 | 7.1v3.1 | POC | — | Low | Low | no | 0.0 | MLflow | MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. Prior to 3.15.0, CreateModelVersion accepts a run_id or model_id after _validate_source_run() or _validate_source_model() in mlflow/server/handlers.py verifies only path containment, allo |
| CVE-2026-8147 | 2026-07-02 | 8.1v3.0 | POC | — | Low | Low | no | 0.0 | mlflow/mlflow | In MLflow versions prior to 3.14.0, when running with authentication enabled, the trace API endpoints lack proper authorization validators. This allows any authenticated user to bypass experiment-level authorization controls on all trace operations, including reading, deleting, and modifying traces |
| CVE-2026-4035 | 2026-06-03 | 9.1v3.0 | POC | — | Low | Low | no | 0.0 | mlflow/mlflow | A vulnerability in mlflow/mlflow versions prior to 3.11.0 allows for the resolution of environment variables in AI Gateway secrets, which can be exploited to exfiltrate sensitive server-side environment credentials to an attacker-controlled endpoint. This issue arises because the `api_key` field in |
| CVE-2026-3198 | 2026-06-02 | 6.5v3.0 | POC | — | Low | Low | no | 0.0 | mlflow/mlflow | MLflow 3.9.0 with basic-auth (`--app-name basic-auth`) fails to enforce authorization checks for multiple Gateway API 'list' endpoints. Specifically, the `BEFORE_REQUEST_HANDLERS` dictionary in `mlflow/server/auth/__init__.py` does not include entries for `ListGatewaySecretInfos`, `ListGatewayEndpoi |
| CVE-2026-2734 | 2026-05-21 | 6.5v3.0 | POC | — | Low | Low | no | 0.0 | mlflow/mlflow | In mlflow/mlflow versions up to 3.9.0, the `SearchModelVersions` REST API endpoint and the `mlflowSearchModelVersions` GraphQL query lack proper per-model authorization checks when basic authentication is enabled. This allows any authenticated user to enumerate all model versions across all register |
| CVE-2026-2652 | 2026-05-15 | 8.6v3.0 | POC | — | Low | None | YES | 0.0 | mlflow/mlflow | A vulnerability in mlflow/mlflow versions 3.9.0 and earlier allows unauthenticated access to certain FastAPI routes when the server is started with authentication enabled (`--app-name basic-auth`) and served via uvicorn (ASGI). The FastAPI permission middleware only enforces authentication on `/gate |
| CVE-2026-2393 | 2026-05-11 | 7.1v3.0 | POC | — | Low | Low | no | 0.0 | mlflow/mlflow | A Server-Side Request Forgery (SSRF) vulnerability exists in MLflow versions prior to 3.9.0. The `_create_webhook()` function in `mlflow/server/handlers.py` accepts a user-controlled `url` parameter without validation, and the `_send_webhook_request()` function in `mlflow/webhooks/delivery.py` sends |
| CVE-2026-2614 | 2026-05-11 | 7.5v3.0 | POC | — | Low | None | YES | 0.0 | mlflow/mlflow | A vulnerability in the `_create_model_version()` handler of `mlflow/server/handlers.py` in mlflow/mlflow versions 3.9.0 and earlier allows an unauthenticated remote attacker to read arbitrary files from the server's filesystem. The issue arises when a `CreateModelVersion` request includes the tag `m |
| CVE-2026-33866 | 2026-04-07 | 5.3v4.0 | POC | — | Low | Low | YES | 0.0 | MLflow | MLflow is vulnerable to an authorization bypass affecting the AJAX endpoint used to download saved model artifacts. Due to missing access‑control validation, a user without permissions to a given experiment can directly query this endpoint and retrieve model artifacts they are not authorized to acce |
| CVE-2026-0545 | 2026-04-03 | 9.1v3.0 | POC | — | Low | None | YES | 0.0 | mlflow/mlflow | In mlflow/mlflow, the FastAPI job endpoints under `/ajax-api/3.0/jobs/*` are not protected by authentication or authorization when the `basic-auth` app is enabled. This vulnerability affects the latest version of the repository. If job execution is enabled (`MLFLOW_SERVER_ENABLE_JOB_EXECUTION=true`) |
| CVE-2025-15379 | 2026-03-30 | 10.0v3.0 | POC | — | Low | None | YES | 0.0 | mlflow/mlflow | A command injection vulnerability exists in MLflow's model serving container initialization code, specifically in the `_install_model_dependencies_to_env()` function. When deploying a model with `env_manager=LOCAL`, MLflow reads dependency specifications from the model artifact's `python_env.yaml` f |
| CVE-2025-15381 | 2026-03-27 | 8.1v3.0 | POC | — | Low | Low | no | 0.0 | mlflow/mlflow | In the latest version of mlflow/mlflow, when the `basic-auth` app is enabled, tracing and assessment endpoints are not protected by permission validators. This allows any authenticated user, including those with `NO_PERMISSIONS` on the experiment, to read trace information and create assessments for |
| CVE-2024-6838 | 2025-03-20 | 5.3v3.0 | POC | — | Low | None | YES | 0.0 | mlflow/mlflow | In mlflow/mlflow version v2.13.2, a vulnerability exists that allows the creation or renaming of an experiment with a large number of integers in its name due to the lack of a limit on the experiment name. This can cause the MLflow UI panel to become unresponsive, leading to a potential denial of se |
| CVE-2024-8859 | 2025-03-20 | 7.5v3.0 | POC | — | Low | None | YES | 0.0 | mlflow/mlflow | A path traversal vulnerability exists in mlflow/mlflow version 2.15.1. When users configure and use the dbfs service, concatenating the URL directly into the file protocol results in an arbitrary file read vulnerability. This issue occurs because only the path part of the URL is checked, while parts |
| CVE-2025-0453 | 2025-03-20 | 5.9v3.0 | POC | — | High | None | no | 0.0 | mlflow/mlflow | In mlflow/mlflow version 2.17.2, the `/graphql` endpoint is vulnerable to a denial of service attack. An attacker can create large batches of queries that repeatedly request all runs from a given experiment. This can tie up all the workers allocated by MLFlow, rendering the application unable to res |
| CVE-2025-1474 | 2025-03-20 | 3.8v3.0 | POC | — | Low | High | no | 0.0 | mlflow/mlflow | In mlflow/mlflow version 2.18, an admin is able to create a new user account without setting a password. This vulnerability could lead to security risks, as accounts without passwords may be susceptible to unauthorized access. Additionally, this issue violates best practices for secure user account |
| CVE-2024-0520 | 2024-06-06 | 10.0v3.0 | POC | — | Low | None | no | 0.0 | mlflow/mlflow | A vulnerability in mlflow/mlflow version 8.2.1 allows for remote code execution due to improper neutralization of special elements used in an OS command ('Command Injection') within the `mlflow.data.http_dataset_source.py` module. Specifically, when loading a dataset from a source URL with an HTTP s |
| CVE-2024-3099 | 2024-06-06 | 5.4v3.0 | POC | — | Low | Low | no | 0.0 | mlflow/mlflow | A vulnerability in mlflow/mlflow version 2.11.1 allows attackers to create multiple models with the same name by exploiting URL encoding. This flaw can lead to Denial of Service (DoS) as an authenticated user might not be able to use the intended model, as it will open a different model each time. A |
| CVE-2024-3848 | 2024-05-16 | 7.5v3.0 | POC | — | Low | None | YES | 0.0 | mlflow/mlflow | A path traversal vulnerability exists in mlflow/mlflow version 2.11.0, identified as a bypass for the previously addressed CVE-2023-6909. The vulnerability arises from the application's handling of artifact URLs, where a '#' character can be used to insert a path into the fragment, effectively skipp |
| CVE-2024-1483 | 2024-04-16 | 7.5v3.0 | POC | — | Low | None | YES | 0.0 | mlflow/mlflow | A path traversal vulnerability exists in mlflow/mlflow version 2.9.2, allowing attackers to access arbitrary files on the server. By crafting a series of HTTP POST requests with specially crafted 'artifact_location' and 'source' parameters, using a local URI with '#' instead of '?', an attacker can |
| CVE-2024-1558 | 2024-04-16 | 7.5v3.0 | POC | — | Low | None | YES | 0.0 | mlflow/mlflow | A path traversal vulnerability exists in the `_create_model_version()` function within `server/handlers.py` of the mlflow/mlflow repository, due to improper validation of the `source` parameter. Attackers can exploit this vulnerability by crafting a `source` parameter that bypasses the `_validate_no |
| CVE-2024-1560 | 2024-04-16 | 8.1v3.0 | POC | — | Low | Low | no | 0.0 | mlflow/mlflow | A path traversal vulnerability exists in the mlflow/mlflow repository, specifically within the artifact deletion functionality. Attackers can bypass path validation by exploiting the double decoding process in the `_delete_artifact_mlflow_artifacts` handler and `local_file_uri_to_path` function, all |
| CVE-2024-1593 | 2024-04-16 | 7.5v3.0 | POC | — | Low | None | YES | 0.0 | mlflow/mlflow | A path traversal vulnerability exists in the mlflow/mlflow repository due to improper handling of URL parameters. By smuggling path traversal sequences using the ';' character in URLs, attackers can manipulate the 'params' portion of the URL to gain unauthorized access to files or directories. This |
| CVE-2024-1594 | 2024-04-16 | 7.5v3.0 | POC | — | Low | None | YES | 0.0 | mlflow/mlflow | A path traversal vulnerability exists in the mlflow/mlflow repository, specifically within the handling of the `artifact_location` parameter when creating an experiment. Attackers can exploit this vulnerability by using a fragment component `#` in the artifact location URI to read arbitrary files on |
| CVE-2024-3573 | 2024-04-16 | 9.3v3.0 | POC | — | Low | None | YES | 0.0 | mlflow/mlflow | mlflow/mlflow is vulnerable to Local File Inclusion (LFI) due to improper parsing of URIs, allowing attackers to bypass checks and read arbitrary files on the system. The issue arises from the 'is_local_uri' function's failure to properly handle URIs with empty or 'file' schemes, leading to the misc |
| CVE-2023-6709 | 2023-12-12 | 10.0v3.0 | POC | — | Low | None | YES | 0.0 | mlflow/mlflow | Improper Neutralization of Special Elements Used in a Template Engine in GitHub repository mlflow/mlflow prior to 2.9.2. |
| CVE-2023-6014 | 2023-11-16 | 9.1v3.0 | POC | — | Low | None | YES | 0.0 | mlflow/mlflow | An attacker is able to arbitrarily create an account in MLflow bypassing any authentication requirment. |
Each CVE: 10 pts base (Active only), boosted by:
KEV×2.0AC: Low×1.2PR: None×1.3PR: Low×1.1Auto×1.3