{"data":{"ecosystem":"pypi","name":"mlflow","url":"https://aisecwatch.com/packages/pypi/mlflow","latestVersion":"3.17.0","firstReleaseAt":"2018-06-04T22:03:34.629Z","repository":"https://github.com/mlflow/mlflow","llm":{"exposure":"direct","depth":0,"integratedAt":"2024-05-30T15:30:04.968Z","integratedVersion":"2.13.1","sdks":["fastmcp","langchain"],"path":[]},"authority":{"profile":["execution","http","mcp_tools"],"fromDependencies":["pypi:aiohttp","pypi:docker","pypi:fastmcp"]},"dependencies":[{"ecosystem":"pypi","name":"fastmcp","versionSpec":"<4,>=2.7.0","scope":"extra:mcp"},{"ecosystem":"pypi","name":"langchain","versionSpec":"<=1.4.3,>=1.0.0","scope":"extra:langchain"},{"ecosystem":"pypi","name":"mlflow-skinny","versionSpec":"==3.17.0","scope":"runtime"},{"ecosystem":"pypi","name":"aliyunstoreplugin","versionSpec":null,"scope":"extra:aliyun-oss"},{"ecosystem":"pypi","name":"databricks-agents","versionSpec":"<2.0,>=1.2.0","scope":"extra:databricks"},{"ecosystem":"pypi","name":"mlflow-dbstore","versionSpec":null,"scope":"extra:sqlserver"},{"ecosystem":"pypi","name":"mlflow-jfrog-plugin","versionSpec":null,"scope":"extra:jfrog"},{"ecosystem":"pypi","name":"mlflow-tracing","versionSpec":"==3.17.0","scope":"runtime"},{"ecosystem":"pypi","name":"aiohttp","versionSpec":"<4,>=3.7.0","scope":"runtime"},{"ecosystem":"pypi","name":"alembic","versionSpec":"!=1.10.0,<2","scope":"runtime"},{"ecosystem":"pypi","name":"azure-identity","versionSpec":">=1.6.1","scope":"extra:azure"},{"ecosystem":"pypi","name":"azureml-core","versionSpec":">=1.2.0","scope":"extra:extras"},{"ecosystem":"pypi","name":"azure-storage-blob","versionSpec":">=12","scope":"extra:azure"},{"ecosystem":"pypi","name":"azure-storage-file-datalake","versionSpec":">12","scope":"extra:databricks"},{"ecosystem":"pypi","name":"boto3","versionSpec":null,"scope":"extra:extras"},{"ecosystem":"pypi","name":"botocore","versionSpec":null,"scope":"extra:extras"},{"ecosystem":"pypi","name":"click","versionSpec":"!=8.3.0","scope":"extra:mcp"},{"ecosystem":"pypi","name":"cryptography","versionSpec":"<51,>=43.0.0","scope":"runtime"},{"ecosystem":"pypi","name":"docker","versionSpec":"<8,>=4.0.0","scope":"runtime"},{"ecosystem":"pypi","name":"fastapi","versionSpec":"<1","scope":"extra:gateway"},{"ecosystem":"pypi","name":"flask","versionSpec":"<4","scope":"runtime"},{"ecosystem":"pypi","name":"flask-cors","versionSpec":"<7","scope":"runtime"},{"ecosystem":"pypi","name":"flask-wtf","versionSpec":"<2","scope":"extra:auth"},{"ecosystem":"pypi","name":"google-cloud-storage","versionSpec":">=1.30.0","scope":"extra:extras"},{"ecosystem":"pypi","name":"graphene","versionSpec":"<4","scope":"runtime"},{"ecosystem":"pypi","name":"gunicorn","versionSpec":"<27","scope":"runtime"},{"ecosystem":"pypi","name":"huey","versionSpec":"<4,>=2.5.4","scope":"runtime"},{"ecosystem":"pypi","name":"kubernetes","versionSpec":null,"scope":"extra:extras"},{"ecosystem":"pypi","name":"matplotlib","versionSpec":"<4","scope":"runtime"},{"ecosystem":"pypi","name":"numpy","versionSpec":"<3","scope":"runtime"},{"ecosystem":"pypi","name":"pandas","versionSpec":"<4","scope":"runtime"},{"ecosystem":"pypi","name":"prometheus-flask-exporter","versionSpec":null,"scope":"extra:extras"},{"ecosystem":"pypi","name":"psycopg","versionSpec":null,"scope":"extra:db"},{"ecosystem":"pypi","name":"psycopg2-binary","versionSpec":null,"scope":"extra:db"},{"ecosystem":"pypi","name":"pyarrow","versionSpec":"<26,>=4.0.0","scope":"runtime"},{"ecosystem":"pypi","name":"pymssql","versionSpec":null,"scope":"extra:db"},{"ecosystem":"pypi","name":"pymysql","versionSpec":null,"scope":"extra:db"},{"ecosystem":"pypi","name":"pysftp","versionSpec":null,"scope":"extra:extras"},{"ecosystem":"pypi","name":"requests-auth-aws-sigv4","versionSpec":null,"scope":"extra:extras"},{"ecosystem":"pypi","name":"scikit-learn","versionSpec":"<2","scope":"runtime"},{"ecosystem":"pypi","name":"scipy","versionSpec":"<2","scope":"runtime"},{"ecosystem":"pypi","name":"skops","versionSpec":"<1","scope":"runtime"},{"ecosystem":"pypi","name":"slowapi","versionSpec":"<1,>=0.1.9","scope":"extra:gateway"},{"ecosystem":"pypi","name":"sqlalchemy","versionSpec":"<3,>=1.4.0","scope":"runtime"},{"ecosystem":"pypi","name":"tiktoken","versionSpec":"<1","scope":"extra:gateway"},{"ecosystem":"pypi","name":"uvicorn","versionSpec":"<1","scope":"extra:gateway"},{"ecosystem":"pypi","name":"waitress","versionSpec":"<4","scope":"runtime"},{"ecosystem":"pypi","name":"watchfiles","versionSpec":"<2","scope":"extra:gateway"}],"advisories":[{"id":"e0d1a2d5-c714-4505-b564-91c292acc356","url":"https://aisecwatch.com/issues/e0d1a2d5-c714-4505-b564-91c292acc356","cveId":null,"title":"GHSA-gqvg-gmmx-x4hm: MLFLOW_ALLOW_PICKLE_DESERIALIZATION=False safety control bypassed by mlflow.statsmodels flavor — RCE via crafted model artifact","headline":null,"severity":"high","publishedAt":"2026-09-01T17:04:30.000Z","affected":["mlflow@>= 2.1.0, < 3.15.0 (fixed: 3.15.0)"],"epssScore":null,"matchedBy":"ecosystem"},{"id":"73042575-5255-4246-8b54-8130bc8d9128","url":"https://aisecwatch.com/issues/73042575-5255-4246-8b54-8130bc8d9128","cveId":"CVE-2026-64849","title":"GHSA-7gwp-5pfp-969j: MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding)","headline":null,"severity":"critical","publishedAt":"2026-08-17T21:58:51.000Z","affected":["mlflow@< 3.15.0 (fixed: 3.15.0)"],"epssScore":0.09839,"matchedBy":"ecosystem"},{"id":"b9a51ff6-0c88-4aec-8f0d-b8d05526f4e8","url":"https://aisecwatch.com/issues/b9a51ff6-0c88-4aec-8f0d-b8d05526f4e8","cveId":"CVE-2026-71211","title":"CVE-2026-71211: MLflow's AI Gateway accepts an auth_config.api_base value when creating a gateway secret (mlflow/server/handlers.py…","headline":"MLflow AI Gateway SSRF via unvalidated api_base in gateway secrets","severity":"high","publishedAt":"2026-08-05T08:16:43.367Z","affected":["mlflow@>= 3.13.0, <= 3.15.2"],"epssScore":0.0029,"matchedBy":"ecosystem"},{"id":"7997461c-efb6-49a2-8b68-7b28dbc0ee08","url":"https://aisecwatch.com/issues/7997461c-efb6-49a2-8b68-7b28dbc0ee08","cveId":"CVE-2026-8147","title":"CVE-2026-8147: In MLflow versions prior to 3.14.0, when running with authentication enabled, the trace API endpoints lack proper…","headline":"MLflow trace API missing authorization checks allowing unauthorized access","severity":"high","publishedAt":"2026-07-02T09:16:19.100Z","affected":["mlflow@>= 2.14.0rc0, < 3.13.0rc0 (fixed: 3.13.0rc0)"],"epssScore":0.00548,"matchedBy":"ecosystem"},{"id":"21622554-53db-4e4e-8b1c-f1f635d69608","url":"https://aisecwatch.com/issues/21622554-53db-4e4e-8b1c-f1f635d69608","cveId":"CVE-2026-10803","title":"CVE-2026-10803: A flaw has been found in MLflow up to 3.10.0. This issue affects the function mlflow.data.digest_utils of the file…","headline":"MLflow weak hash in Dataset Digest Computation via digest_utils","severity":"low","publishedAt":"2026-06-04T12:16:24.440Z","affected":["mlflow@< 3.10.1 (fixed: 3.10.1)"],"epssScore":0.00103,"matchedBy":"ecosystem"},{"id":"3374adbd-42f4-45f3-b65a-1d0046ed8904","url":"https://aisecwatch.com/issues/3374adbd-42f4-45f3-b65a-1d0046ed8904","cveId":"CVE-2026-3198","title":"CVE-2026-3198: MLflow 3.9.0 with basic-auth (`--app-name basic-auth`) fails to enforce authorization checks for multiple Gateway API…","headline":"MLflow basic-auth flaw lets any user list Gateway secrets and endpoints","severity":"high","publishedAt":"2026-06-02T04:17:03.397Z","affected":["mlflow@< 3.11.0rc0 (fixed: 3.11.0rc0)"],"epssScore":0.00358,"matchedBy":"ecosystem"},{"id":"70c0ca8e-6181-4b8b-8544-718a07ac1c70","url":"https://aisecwatch.com/issues/70c0ca8e-6181-4b8b-8544-718a07ac1c70","cveId":"CVE-2026-2734","title":"CVE-2026-2734: In mlflow/mlflow versions up to 3.9.0, the `SearchModelVersions` REST API endpoint and the `mlflowSearchModelVersions`…","headline":"mlflow SearchModelVersions lacks per-model authorization checks","severity":"medium","publishedAt":"2026-05-21T05:16:22.723Z","affected":["mlflow@< 3.10.0 (fixed: 3.10.0)"],"epssScore":0.00502,"matchedBy":"ecosystem"},{"id":"6bc9bcf5-c7de-4e66-8059-5bbb48503054","url":"https://aisecwatch.com/issues/6bc9bcf5-c7de-4e66-8059-5bbb48503054","cveId":"CVE-2026-2611","title":"CVE-2026-2611: In MLflow version 3.9.0, the MLflow Assistant feature introduced improper origin validation in its /ajax-api endpoints…","headline":"MLflow Assistant improper origin validation in /ajax-api endpoints","severity":"high","publishedAt":"2026-05-19T10:16:22.983Z","affected":["mlflow@= 3.9.0 (fixed: 3.10.0)"],"epssScore":0.00414,"matchedBy":"ecosystem"},{"id":"cdc30758-e5a8-4348-9e1b-8c8a7c6f00b3","url":"https://aisecwatch.com/issues/cdc30758-e5a8-4348-9e1b-8c8a7c6f00b3","cveId":"CVE-2026-4137","title":"CVE-2026-4137: In mlflow/mlflow versions prior to 3.11.0, the `get_or_create_nfs_tmp_dir()` function in `mlflow/utils/file_utils.py`…","headline":"mlflow insecure temporary directory permissions enable code execution","severity":"high","publishedAt":"2026-05-18T21:16:40.710Z","affected":["mlflow@>= 1.26.0, < 3.11.0 (fixed: 3.11.0)"],"epssScore":0.00162,"matchedBy":"ecosystem"},{"id":"93a99aed-5225-4ce5-968b-70257532978a","url":"https://aisecwatch.com/issues/93a99aed-5225-4ce5-968b-70257532978a","cveId":"CVE-2026-2652","title":"CVE-2026-2652: A vulnerability in mlflow/mlflow versions 3.9.0 and earlier allows unauthenticated access to certain FastAPI routes…","headline":"mlflow authentication bypass on FastAPI routes allows unauthenticated job access","severity":"high","publishedAt":"2026-05-15T03:16:23.127Z","affected":["mlflow@< 3.11.0 (fixed: 3.11.0)"],"epssScore":0.01409,"matchedBy":"ecosystem"},{"id":"3ad8ba51-252f-4e90-8e81-a1458be25dab","url":"https://aisecwatch.com/issues/3ad8ba51-252f-4e90-8e81-a1458be25dab","cveId":"CVE-2026-2614","title":"CVE-2026-2614: A vulnerability in the `_create_model_version()` handler of `mlflow/server/handlers.py` in mlflow/mlflow versions 3.9.0…","headline":"MLflow arbitrary file read through model version creation handler","severity":"high","publishedAt":"2026-05-11T20:25:41.423Z","affected":["mlflow@< 3.10.0 (fixed: 3.10.0)"],"epssScore":0.03206,"matchedBy":"ecosystem"},{"id":"2df4c88f-7a86-4c20-9bf4-900326cc4271","url":"https://aisecwatch.com/issues/2df4c88f-7a86-4c20-9bf4-900326cc4271","cveId":"CVE-2026-2393","title":"CVE-2026-2393: A Server-Side Request Forgery (SSRF) vulnerability exists in MLflow versions prior to 3.9.0. The `_create_webhook()`…","headline":"MLflow server-side request forgery through webhook URL creation","severity":"high","publishedAt":"2026-05-11T18:16:31.500Z","affected":["mlflow@< 3.9.0 (fixed: 3.9.0)"],"epssScore":0.00288,"matchedBy":"ecosystem"},{"id":"b813dc50-4652-4520-abad-83c291944353","url":"https://aisecwatch.com/issues/b813dc50-4652-4520-abad-83c291944353","cveId":"CVE-2026-33866","title":"CVE-2026-33866: MLflow is vulnerable to an authorization bypass affecting the AJAX endpoint used to download saved model artifacts. Due…","headline":"MLflow authorization bypass in AJAX endpoint for model artifact downloads","severity":"medium","publishedAt":"2026-04-07T13:16:47.000Z","affected":["mlflow@<= 3.10.1 (fixed: 3.11.0rc0)"],"epssScore":0.00374,"matchedBy":"ecosystem"},{"id":"af4f3700-a85f-4c21-a683-50ded2e70464","url":"https://aisecwatch.com/issues/af4f3700-a85f-4c21-a683-50ded2e70464","cveId":"CVE-2026-33865","title":"CVE-2026-33865: MLflow is vulnerable to Stored Cross-Site Scripting (XSS) caused by unsafe parsing of YAML-based MLmodel artifacts in…","headline":"MLflow stored cross-site scripting through YAML-based MLmodel artifacts","severity":"medium","publishedAt":"2026-04-07T13:16:46.840Z","affected":["mlflow@<= 3.10.1 (fixed: 3.11.1)"],"epssScore":0.003,"matchedBy":"ecosystem"},{"id":"c169107e-ad26-4193-92ad-5ddd68a07ab2","url":"https://aisecwatch.com/issues/c169107e-ad26-4193-92ad-5ddd68a07ab2","cveId":"CVE-2026-0545","title":"CVE-2026-0545: In mlflow/mlflow, the FastAPI job endpoints under `/ajax-api/3.0/jobs/*` are not protected by authentication or…","headline":"mlflow job endpoints lack authentication when basic-auth is enabled","severity":"critical","publishedAt":"2026-04-03T18:16:21.540Z","affected":["mlflow@<= 3.10.1"],"epssScore":0.04392,"matchedBy":"ecosystem"},{"id":"19288232-d05b-4e64-a98b-ba37b6e8d835","url":"https://aisecwatch.com/issues/19288232-d05b-4e64-a98b-ba37b6e8d835","cveId":"CVE-2026-0596","title":"CVE-2026-0596: A command injection vulnerability exists in mlflow/mlflow when serving a model with `enable_mlserver=True`. The…","headline":"mlflow command injection through model_uri when serving with enable_mlserver","severity":"high","publishedAt":"2026-03-31T15:16:10.843Z","affected":["mlflow@< 3.9.0 (fixed: 3.9.0)"],"epssScore":0.01328,"matchedBy":"ecosystem"},{"id":"0d1aaf56-b6e4-4081-b641-b1b8e9d89dc9","url":"https://aisecwatch.com/issues/0d1aaf56-b6e4-4081-b641-b1b8e9d89dc9","cveId":"CVE-2025-15379","title":"CVE-2025-15379: A command injection vulnerability exists in MLflow's model serving container initialization code, specifically in the…","headline":"MLflow command injection in model serving dependency installation","severity":"high","publishedAt":"2026-03-30T08:16:15.667Z","affected":["mlflow@< 3.8.1 (fixed: 3.8.1)"],"epssScore":0.02359,"matchedBy":"ecosystem"},{"id":"da5f1e01-daf1-4b17-8f1c-e4f037d9db37","url":"https://aisecwatch.com/issues/da5f1e01-daf1-4b17-8f1c-e4f037d9db37","cveId":"CVE-2025-15036","title":"CVE-2025-15036: A path traversal vulnerability exists in the `extract_archive_to_dir` function within the…","headline":"MLflow path traversal in extract_archive_to_dir during tar extraction","severity":"high","publishedAt":"2026-03-30T02:16:14.413Z","affected":["mlflow@< 3.9.0rc0 (fixed: 3.9.0rc0)"],"epssScore":0.00579,"matchedBy":"ecosystem"},{"id":"6ffc0a9a-08ab-42a8-8987-36ca1b90ba95","url":"https://aisecwatch.com/issues/6ffc0a9a-08ab-42a8-8987-36ca1b90ba95","cveId":"CVE-2025-15381","title":"CVE-2025-15381: In the latest version of mlflow/mlflow, when the `basic-auth` app is enabled, tracing and assessment endpoints are not…","headline":"MLflow basic-auth app lacks permission checks on tracing endpoints","severity":"medium","publishedAt":"2026-03-27T17:16:26.573Z","affected":["mlflow@<= 3.8.1"],"epssScore":0.00331,"matchedBy":"ecosystem"},{"id":"92922b5b-e21e-40c9-9aae-7f16c14fafad","url":"https://aisecwatch.com/issues/92922b5b-e21e-40c9-9aae-7f16c14fafad","cveId":"CVE-2025-15031","title":"CVE-2025-15031: A vulnerability in MLflow's pyfunc extraction process allows for arbitrary file writes due to improper handling of tar…","headline":"MLflow arbitrary file write during pyfunc extraction via tar archive entries","severity":"high","publishedAt":"2026-03-18T23:17:28.693Z","affected":["mlflow@< 3.9.0rc0 (fixed: 3.9.0rc0)"],"epssScore":0.00852,"matchedBy":"ecosystem"},{"id":"c328deb8-9b1d-4d24-bac4-d6265fd4b460","url":"https://aisecwatch.com/issues/c328deb8-9b1d-4d24-bac4-d6265fd4b460","cveId":"CVE-2025-14287","title":"CVE-2025-14287: A command injection vulnerability exists in mlflow/mlflow versions before v3.7.0, specifically in the…","headline":"MLflow command injection through the container parameter in SageMaker CLI","severity":"high","publishedAt":"2026-03-16T14:17:55.610Z","affected":["mlflow@< 3.8.0rc0 (fixed: 3.8.0rc0)"],"epssScore":0.01456,"matchedBy":"ecosystem"},{"id":"93b6298f-8f30-49bf-a14b-67cc38ba959c","url":"https://aisecwatch.com/issues/93b6298f-8f30-49bf-a14b-67cc38ba959c","cveId":"CVE-2026-2635","title":"CVE-2026-2635: MLflow Use of Default Password Authentication Bypass Vulnerability. This vulnerability allows remote attackers to…","headline":"MLflow authentication bypass through default credentials in basic_auth.ini","severity":"critical","publishedAt":"2026-02-20T23:16:05.577Z","affected":["mlflow@< 3.8.0rc0 (fixed: 3.8.0rc0)"],"epssScore":0.01242,"matchedBy":"ecosystem"},{"id":"75b46f6c-5146-4b21-bd5e-da1f79969db0","url":"https://aisecwatch.com/issues/75b46f6c-5146-4b21-bd5e-da1f79969db0","cveId":"CVE-2026-2033","title":"CVE-2026-2033: MLflow Tracking Server Artifact Handler Directory Traversal Remote Code Execution Vulnerability. This vulnerability…","headline":"MLflow Tracking Server directory traversal in artifact handler file paths","severity":"high","publishedAt":"2026-02-20T23:16:03.093Z","affected":["mlflow@< 3.8.0rc0 (fixed: 3.8.0rc0)"],"epssScore":0.01728,"matchedBy":"ecosystem"},{"id":"c239ca46-17da-47dc-bf3b-58b5c068de29","url":"https://aisecwatch.com/issues/c239ca46-17da-47dc-bf3b-58b5c068de29","cveId":"CVE-2025-10279","title":"CVE-2025-10279: In mlflow version 2.20.3, the temporary directory used for creating Python virtual environments is assigned insecure…","headline":"mlflow world-writable temp directory allows code execution","severity":"high","publishedAt":"2026-02-02T16:16:16.867Z","affected":["mlflow@< 3.4.0rc0 (fixed: 3.4.0rc0)"],"epssScore":0.00244,"matchedBy":"ecosystem"},{"id":"b042c14b-1e16-4768-8a13-4f16edb26eea","url":"https://aisecwatch.com/issues/b042c14b-1e16-4768-8a13-4f16edb26eea","cveId":"CVE-2025-14279","title":"CVE-2025-14279: MLFlow versions up to and including 3.4.0 are vulnerable to DNS rebinding attacks due to a lack of Origin header…","headline":"MLFlow DNS rebinding through missing Origin header validation in REST server","severity":"high","publishedAt":"2026-01-12T14:15:50.577Z","affected":["mlflow@< 3.5.0 (fixed: 3.5.0)"],"epssScore":0.00216,"matchedBy":"ecosystem"},{"id":"62a5714a-58e4-44df-99e5-40f40f77b5c2","url":"https://aisecwatch.com/issues/62a5714a-58e4-44df-99e5-40f40f77b5c2","cveId":"CVE-2025-11201","title":"CVE-2025-11201: MLflow Tracking Server Model Creation Directory Traversal Remote Code Execution Vulnerability. This vulnerability…","headline":"MLflow Tracking Server directory traversal leads to code execution","severity":"critical","publishedAt":"2025-10-30T00:15:35.680Z","affected":["mlflow@>= 3.0.0rc0, < 3.0.0 (fixed: 3.0.0)","mlflow@< 2.22.4 (fixed: 2.22.4)"],"epssScore":0.26452,"matchedBy":"ecosystem"},{"id":"6baf45a0-98a5-4b15-aac4-39ab8109cd71","url":"https://aisecwatch.com/issues/6baf45a0-98a5-4b15-aac4-39ab8109cd71","cveId":"CVE-2025-11200","title":"CVE-2025-11200: MLflow Weak Password Requirements Authentication Bypass Vulnerability. This vulnerability allows remote attackers to…","headline":"MLflow authentication bypass through weak password requirements","severity":"critical","publishedAt":"2025-10-30T00:15:35.543Z","affected":["mlflow@< 2.22.0rc0 (fixed: 2.22.0rc0)"],"epssScore":0.01439,"matchedBy":"ecosystem"},{"id":"8ca782ba-a5eb-4034-bb2a-154c670b435f","url":"https://aisecwatch.com/issues/8ca782ba-a5eb-4034-bb2a-154c670b435f","cveId":"CVE-2025-52967","title":"CVE-2025-52967: gateway_proxy_handler in MLflow before 3.1.0 lacks gateway_path validation.","headline":"MLflow gateway_proxy_handler server-side request forgery via gateway_path","severity":"medium","publishedAt":"2025-06-23T19:15:29.163Z","affected":["mlflow@>= 3.0.0rc0, < 3.1.0 (fixed: 3.1.0)","mlflow@< 2.22.2 (fixed: 2.22.2)"],"epssScore":0.00438,"matchedBy":"ecosystem"},{"id":"f40491fd-d1fc-435b-bd89-c133c54f48cd","url":"https://aisecwatch.com/issues/f40491fd-d1fc-435b-bd89-c133c54f48cd","cveId":"CVE-2025-1474","title":"CVE-2025-1474: In mlflow/mlflow version 2.18, an admin is able to create a new user account without setting a password. This…","headline":"MLflow admin can create user accounts without setting a password","severity":"medium","publishedAt":"2025-03-20T14:15:54.037Z","affected":["mlflow@< 2.19.0 (fixed: 2.19.0)"],"epssScore":0.00359,"matchedBy":"ecosystem"},{"id":"11759f9e-705c-448d-a831-4c80a65fe9f1","url":"https://aisecwatch.com/issues/11759f9e-705c-448d-a831-4c80a65fe9f1","cveId":"CVE-2025-1473","title":"CVE-2025-1473: A Cross-Site Request Forgery (CSRF) vulnerability exists in the Signup feature of mlflow/mlflow versions 2.17.0 to…","headline":"mlflow Cross-Site Request Forgery in the Signup feature","severity":"high","publishedAt":"2025-03-20T14:15:53.903Z","affected":["mlflow@>= 2.17.0, < 2.20.3 (fixed: 2.20.3)"],"epssScore":0.00216,"matchedBy":"ecosystem"},{"id":"6159d8ea-0db6-45be-a80e-09dc58b64675","url":"https://aisecwatch.com/issues/6159d8ea-0db6-45be-a80e-09dc58b64675","cveId":"CVE-2025-0453","title":"CVE-2025-0453: In mlflow/mlflow version 2.17.2, the `/graphql` endpoint is vulnerable to a denial of service attack. An attacker can…","headline":"mlflow denial of service through the /graphql endpoint","severity":"high","publishedAt":"2025-03-20T14:15:53.017Z","affected":["mlflow@<= 2.17.2"],"epssScore":0.11033,"matchedBy":"ecosystem"},{"id":"20c0109e-f096-4e45-b9f6-a514cf531565","url":"https://aisecwatch.com/issues/20c0109e-f096-4e45-b9f6-a514cf531565","cveId":"CVE-2024-8859","title":"CVE-2024-8859: A path traversal vulnerability exists in mlflow/mlflow version 2.15.1. When users configure and use the dbfs service…","headline":"mlflow/mlflow path traversal in dbfs service via URL file protocol","severity":"high","publishedAt":"2025-03-20T14:15:44.463Z","affected":["mlflow@< 2.17.0rc0 (fixed: 2.17.0rc0)"],"epssScore":0.02715,"matchedBy":"ecosystem"},{"id":"cc5b9c62-aea5-43da-8345-b6b874843556","url":"https://aisecwatch.com/issues/cc5b9c62-aea5-43da-8345-b6b874843556","cveId":"CVE-2024-6838","title":"CVE-2024-6838: In mlflow/mlflow version v2.13.2, a vulnerability exists that allows the creation or renaming of an experiment with a…","headline":"MLflow experiment name handling flaw enables denial of service via UI","severity":"medium","publishedAt":"2025-03-20T14:15:33.620Z","affected":["mlflow@<= 2.13.2"],"epssScore":0.00652,"matchedBy":"ecosystem"},{"id":"d3de6226-c87f-45fc-aba8-ee2a8ef0a676","url":"https://aisecwatch.com/issues/d3de6226-c87f-45fc-aba8-ee2a8ef0a676","cveId":"CVE-2024-27134","title":"CVE-2024-27134: Excessive directory permissions in MLflow leads to local privilege escalation when using spark_udf. This behavior can…","headline":"MLflow excessive directory permissions enable local privilege escalation","severity":"high","publishedAt":"2024-11-25T19:15:06.867Z","affected":["mlflow@< 2.16.0 (fixed: 2.16.0)"],"epssScore":0.00121,"matchedBy":"ecosystem"},{"id":"2f19f616-ad0c-48c1-af43-bedf56f3471e","url":"https://aisecwatch.com/issues/2f19f616-ad0c-48c1-af43-bedf56f3471e","cveId":"CVE-2024-3099","title":"CVE-2024-3099: A vulnerability in mlflow/mlflow version 2.11.1 allows attackers to create multiple models with the same name by…","headline":"mlflow model registry allows duplicate model names through URL encoding","severity":"medium","publishedAt":"2024-06-06T23:15:59.393Z","affected":["mlflow@< 2.11.3 (fixed: 2.11.3)"],"epssScore":0.00442,"matchedBy":"ecosystem"},{"id":"3cece0af-fd5d-4397-9072-57be613b0472","url":"https://aisecwatch.com/issues/3cece0af-fd5d-4397-9072-57be613b0472","cveId":"CVE-2024-2928","title":"CVE-2024-2928: A Local File Inclusion (LFI) vulnerability was identified in mlflow/mlflow, specifically in version 2.9.2, which was…","headline":"mlflow/mlflow local file inclusion through URI fragment traversal","severity":"high","publishedAt":"2024-06-06T23:15:55.680Z","affected":["mlflow@< 2.11.3 (fixed: 2.11.3)"],"epssScore":0.21847,"matchedBy":"ecosystem"},{"id":"98b53415-cd9f-4390-be49-adc5f57ee23c","url":"https://aisecwatch.com/issues/98b53415-cd9f-4390-be49-adc5f57ee23c","cveId":"CVE-2024-0520","title":"CVE-2024-0520: A vulnerability in mlflow/mlflow version 8.2.1 allows for remote code execution due to improper neutralization of…","headline":"MLflow command injection when loading dataset from HTTP source URL","severity":"high","publishedAt":"2024-06-06T23:15:51.187Z","affected":["mlflow@< 2.9.0 (fixed: 2.9.0)"],"epssScore":0.02401,"matchedBy":"ecosystem"},{"id":"1eb840fe-5f3a-4e3a-9520-c7a22c653a33","url":"https://aisecwatch.com/issues/1eb840fe-5f3a-4e3a-9520-c7a22c653a33","cveId":"CVE-2024-37061","title":"CVE-2024-37061: Remote Code Execution can occur in versions of the MLflow platform running version 1.11.0 or newer, enabling a…","headline":"MLflow remote code execution through maliciously crafted MLproject","severity":"high","publishedAt":"2024-06-04T16:15:12.703Z","affected":["mlflow@>= 1.11.0, <= 2.13.1"],"epssScore":0.00884,"matchedBy":"ecosystem"},{"id":"6d1eace0-34c6-4c38-9edf-f14909faab3b","url":"https://aisecwatch.com/issues/6d1eace0-34c6-4c38-9edf-f14909faab3b","cveId":"CVE-2024-37060","title":"CVE-2024-37060: Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.27.0 or newer…","headline":"MLflow deserialization of untrusted data via malicious Recipe","severity":"high","publishedAt":"2024-06-04T16:15:12.463Z","affected":["mlflow@>= 1.27.0, <= 2.14.1"],"epssScore":0.00775,"matchedBy":"ecosystem"},{"id":"a9c1295a-9b68-4afa-bdf9-d299edb1eaeb","url":"https://aisecwatch.com/issues/a9c1295a-9b68-4afa-bdf9-d299edb1eaeb","cveId":"CVE-2024-37059","title":"CVE-2024-37059: Deserialization of untrusted data can occur in versions of the MLflow platform running version 0.5.0 or newer, enabling…","headline":"MLflow deserialization of untrusted data via malicious PyTorch model","severity":"high","publishedAt":"2024-06-04T16:15:12.227Z","affected":["mlflow@>= 0.5.0, <= 3.4.0"],"epssScore":0.00618,"matchedBy":"ecosystem"},{"id":"070cfb31-c7fe-4477-878a-e9209b1ec93c","url":"https://aisecwatch.com/issues/070cfb31-c7fe-4477-878a-e9209b1ec93c","cveId":"CVE-2024-37058","title":"CVE-2024-37058: Deserialization of untrusted data can occur in versions of the MLflow platform running version 2.5.0 or newer, enabling…","headline":"MLflow deserialization of untrusted data via Langchain AgentExecutor model","severity":"high","publishedAt":"2024-06-04T16:15:12.023Z","affected":["mlflow@>= 2.5.0, <= 2.14.1"],"epssScore":0.00618,"matchedBy":"ecosystem"},{"id":"6928b43a-bb2f-4924-945d-64a3c5f00ec4","url":"https://aisecwatch.com/issues/6928b43a-bb2f-4924-945d-64a3c5f00ec4","cveId":"CVE-2024-37057","title":"CVE-2024-37057: Deserialization of untrusted data can occur in versions of the MLflow platform running version 2.0.0rc0 or newer…","headline":"MLflow deserialization flaw allows code execution via TensorFlow model","severity":"high","publishedAt":"2024-06-04T16:15:11.800Z","affected":["mlflow@>= 2.0.0rc0, <= 2.14.1"],"epssScore":0.00618,"matchedBy":"ecosystem"},{"id":"275e8583-c55d-4637-901a-98027472da00","url":"https://aisecwatch.com/issues/275e8583-c55d-4637-901a-98027472da00","cveId":"CVE-2024-37056","title":"CVE-2024-37056: Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.23.0 or newer…","headline":"MLflow deserialization of untrusted data via uploaded LightGBM model","severity":"high","publishedAt":"2024-06-04T16:15:11.593Z","affected":["mlflow@>= 1.23.0, <= 2.14.1"],"epssScore":0.00618,"matchedBy":"ecosystem"},{"id":"ff1a5715-8f1f-444c-9838-ac1db6f95f11","url":"https://aisecwatch.com/issues/ff1a5715-8f1f-444c-9838-ac1db6f95f11","cveId":"CVE-2024-37055","title":"CVE-2024-37055: Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.24.0 or newer…","headline":"MLflow deserialization flaw allows code execution via pmdarima","severity":"high","publishedAt":"2024-06-04T16:15:11.397Z","affected":["mlflow@>= 1.24.0, <= 2.14.1"],"epssScore":0.00623,"matchedBy":"ecosystem"},{"id":"6b1c8e46-5333-4a90-a8a6-780bbb96e919","url":"https://aisecwatch.com/issues/6b1c8e46-5333-4a90-a8a6-780bbb96e919","cveId":"CVE-2024-37054","title":"CVE-2024-37054: Deserialization of untrusted data can occur in versions of the MLflow platform running version 0.9.0 or newer, enabling…","headline":"MLflow deserialization of untrusted data via malicious PyFunc model","severity":"high","publishedAt":"2024-06-04T16:15:11.190Z","affected":["mlflow@>= 0.9.0, <= 2.14.1"],"epssScore":0.00703,"matchedBy":"ecosystem"},{"id":"8e37dfcc-82b9-48be-86e0-961f12587789","url":"https://aisecwatch.com/issues/8e37dfcc-82b9-48be-86e0-961f12587789","cveId":"CVE-2024-37053","title":"CVE-2024-37053: Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.1.0 or newer, enabling…","headline":"MLflow deserialization of untrusted data via scikit-learn model","severity":"high","publishedAt":"2024-06-04T16:15:10.957Z","affected":["mlflow@>= 1.1.0, <= 2.14.1"],"epssScore":0.00618,"matchedBy":"ecosystem"},{"id":"006b9355-88af-4546-bd4f-dde97d06df86","url":"https://aisecwatch.com/issues/006b9355-88af-4546-bd4f-dde97d06df86","cveId":"CVE-2024-37052","title":"CVE-2024-37052: Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.1.0 or newer, enabling…","headline":"MLflow deserialization of untrusted data via uploaded scikit-learn model","severity":"high","publishedAt":"2024-06-04T16:15:10.413Z","affected":["mlflow@>= 1.1.0, <= 2.14.1"],"epssScore":0.00665,"matchedBy":"ecosystem"},{"id":"71eee6c4-b5d8-4a96-b038-8b0cddcf2105","url":"https://aisecwatch.com/issues/71eee6c4-b5d8-4a96-b038-8b0cddcf2105","cveId":"CVE-2024-4263","title":"CVE-2024-4263: A broken access control vulnerability exists in mlflow/mlflow versions before 2.10.1, where low privilege users with…","headline":"MLflow broken access control allows deleting artifacts with EDIT permission","severity":"medium","publishedAt":"2024-05-16T13:15:16.037Z","affected":["mlflow@< 2.10.1 (fixed: 2.10.1)"],"epssScore":0.00332,"matchedBy":"ecosystem"},{"id":"256eb93f-d402-42bc-9403-2ad2da07ea47","url":"https://aisecwatch.com/issues/256eb93f-d402-42bc-9403-2ad2da07ea47","cveId":"CVE-2024-3848","title":"CVE-2024-3848: A path traversal vulnerability exists in mlflow/mlflow version 2.11.0, identified as a bypass for the previously…","headline":"mlflow/mlflow path traversal in artifact URL handling via fragment","severity":"high","publishedAt":"2024-05-16T13:15:14.543Z","affected":["mlflow@>= 2.9.2, < 2.12.1 (fixed: 2.12.1)"],"epssScore":0.43284,"matchedBy":"ecosystem"},{"id":"56c93900-2621-4b40-b64c-1fc79887bb11","url":"https://aisecwatch.com/issues/56c93900-2621-4b40-b64c-1fc79887bb11","cveId":"CVE-2024-3573","title":"CVE-2024-3573: mlflow/mlflow is vulnerable to Local File Inclusion (LFI) due to improper parsing of URIs, allowing attackers to bypass…","headline":"mlflow/mlflow local file inclusion through improper URI parsing","severity":"critical","publishedAt":"2024-04-16T04:15:12.570Z","affected":["mlflow@< 2.10.0 (fixed: 2.10.0)"],"epssScore":0.00733,"matchedBy":"ecosystem"},{"id":"274c0b49-193d-4cd0-8d38-0b5f60cfe0af","url":"https://aisecwatch.com/issues/274c0b49-193d-4cd0-8d38-0b5f60cfe0af","cveId":"CVE-2024-1594","title":"CVE-2024-1594: A path traversal vulnerability exists in the mlflow/mlflow repository, specifically within the handling of the…","headline":"mlflow path traversal through fragment in artifact_location","severity":"high","publishedAt":"2024-04-16T04:15:09.417Z","affected":["mlflow@<= 2.9.2"],"epssScore":0.00712,"matchedBy":"ecosystem"},{"id":"d60b2623-1bf5-4ca6-97f2-358e67c1d029","url":"https://aisecwatch.com/issues/d60b2623-1bf5-4ca6-97f2-358e67c1d029","cveId":"CVE-2024-1593","title":"CVE-2024-1593: A path traversal vulnerability exists in the mlflow/mlflow repository due to improper handling of URL parameters. By…","headline":"mlflow/mlflow path traversal through URL params using semicolon smuggling","severity":"high","publishedAt":"2024-04-16T04:15:09.247Z","affected":["mlflow@<= 2.9.2"],"epssScore":0.00696,"matchedBy":"ecosystem"},{"id":"2a1a891b-8bd6-4633-9ad2-f5a29e09d459","url":"https://aisecwatch.com/issues/2a1a891b-8bd6-4633-9ad2-f5a29e09d459","cveId":"CVE-2024-1560","title":"CVE-2024-1560: A path traversal vulnerability exists in the mlflow/mlflow repository, specifically within the artifact deletion…","headline":"mlflow path traversal in artifact deletion allows arbitrary directory deletion","severity":"high","publishedAt":"2024-04-16T04:15:08.713Z","affected":["mlflow@<= 2.9.2"],"epssScore":0.00856,"matchedBy":"ecosystem"},{"id":"6da88b1b-362b-4cdf-be90-5a63ff4d3244","url":"https://aisecwatch.com/issues/6da88b1b-362b-4cdf-be90-5a63ff4d3244","cveId":"CVE-2024-1558","title":"CVE-2024-1558: A path traversal vulnerability exists in the `_create_model_version()` function within `server/handlers.py` of the…","headline":"MLflow path traversal in model version creation via source parameter","severity":"high","publishedAt":"2024-04-16T04:15:08.533Z","affected":["mlflow@<= 2.9.2 (fixed: 2.12.1)"],"epssScore":0.00859,"matchedBy":"ecosystem"},{"id":"d8d3afee-f2d8-4046-8784-09b1d168e32c","url":"https://aisecwatch.com/issues/d8d3afee-f2d8-4046-8784-09b1d168e32c","cveId":"CVE-2024-1483","title":"CVE-2024-1483: A path traversal vulnerability exists in mlflow/mlflow version 2.9.2, allowing attackers to access arbitrary files on…","headline":"mlflow path traversal through crafted artifact_location and source parameters","severity":"high","publishedAt":"2024-04-16T04:15:08.353Z","affected":["mlflow@<= 2.9.2 (fixed: 2.12.1)"],"epssScore":0.02718,"matchedBy":"ecosystem"},{"id":"8dfacd8c-c068-4b04-ac17-34eeeb217333","url":"https://aisecwatch.com/issues/8dfacd8c-c068-4b04-ac17-34eeeb217333","cveId":"CVE-2024-27133","title":"CVE-2024-27133: Insufficient sanitization in MLflow leads to XSS when running a recipe that uses an untrusted dataset. This issue leads…","headline":"MLflow XSS through untrusted dataset in recipe run","severity":"high","publishedAt":"2024-02-24T03:15:55.287Z","affected":["mlflow@< 2.10.0 (fixed: 2.10.0)"],"epssScore":0.00656,"matchedBy":"ecosystem"},{"id":"ae3fd6e0-0975-43b2-9bb6-aad097bd07a7","url":"https://aisecwatch.com/issues/ae3fd6e0-0975-43b2-9bb6-aad097bd07a7","cveId":"CVE-2024-27132","title":"CVE-2024-27132: Insufficient sanitization in MLflow leads to XSS when running an untrusted recipe. This issue leads to a client-side RC…","headline":"MLflow XSS through template variables when running an untrusted recipe","severity":"high","publishedAt":"2024-02-24T03:15:55.077Z","affected":["mlflow@< 2.10.0 (fixed: 2.10.0)"],"epssScore":0.00878,"matchedBy":"ecosystem"},{"id":"b5d25e84-f074-4637-a369-1573d5bab545","url":"https://aisecwatch.com/issues/b5d25e84-f074-4637-a369-1573d5bab545","cveId":"CVE-2023-6909","title":"CVE-2023-6909: Path Traversal: '\\..\\filename' in GitHub repository mlflow/mlflow prior to 2.9.2.","headline":"mlflow/mlflow path traversal via crafted \\..\\filename input","severity":"high","publishedAt":"2023-12-18T09:15:52.367Z","affected":["mlflow@< 2.9.2 (fixed: 2.9.2)"],"epssScore":0.89716,"matchedBy":"ecosystem"},{"id":"ed643876-e795-445c-88b4-dac99f36780a","url":"https://aisecwatch.com/issues/ed643876-e795-445c-88b4-dac99f36780a","cveId":"CVE-2023-6831","title":"CVE-2023-6831: Path Traversal: '\\..\\filename' in GitHub repository mlflow/mlflow prior to 2.9.2.","headline":"mlflow/mlflow path traversal via crafted filename","severity":"high","publishedAt":"2023-12-15T06:15:08.140Z","affected":["mlflow@< 2.9.2 (fixed: 2.9.2)"],"epssScore":0.0329,"matchedBy":"ecosystem"},{"id":"d2acd899-5d53-4962-bf6b-ebe7a155d078","url":"https://aisecwatch.com/issues/d2acd899-5d53-4962-bf6b-ebe7a155d078","cveId":"CVE-2023-6753","title":"CVE-2023-6753: Path Traversal in GitHub repository mlflow/mlflow prior to 2.9.2.","headline":"mlflow/mlflow path traversal in GitHub repository","severity":"high","publishedAt":"2023-12-13T05:15:07.330Z","affected":["mlflow@< 2.9.2 (fixed: 2.9.2)"],"epssScore":0.01081,"matchedBy":"ecosystem"},{"id":"0c00a8ab-1317-4233-84e5-7eb9c4a6263d","url":"https://aisecwatch.com/issues/0c00a8ab-1317-4233-84e5-7eb9c4a6263d","cveId":"CVE-2023-6709","title":"CVE-2023-6709: Improper Neutralization of Special Elements Used in a Template Engine in GitHub repository mlflow/mlflow prior to…","headline":"mlflow template engine injection via special element neutralization","severity":"high","publishedAt":"2023-12-12T09:15:07.083Z","affected":["mlflow@< 2.9.2 (fixed: 2.9.2)"],"epssScore":0.00937,"matchedBy":"ecosystem"},{"id":"585ef0e8-2587-40ea-adcf-dce2b8b9ecf2","url":"https://aisecwatch.com/issues/585ef0e8-2587-40ea-adcf-dce2b8b9ecf2","cveId":"CVE-2023-6568","title":"CVE-2023-6568: A reflected Cross-Site Scripting (XSS) vulnerability exists in the mlflow/mlflow repository, specifically within the…","headline":"mlflow reflected cross-site scripting via Content-Type header in POST requests","severity":"medium","publishedAt":"2023-12-07T10:15:09.347Z","affected":["mlflow@< 2.9.0 (fixed: 2.9.0)"],"epssScore":0.01662,"matchedBy":"ecosystem"},{"id":"ba620b24-4a16-45ba-8907-4fb454d4120b","url":"https://aisecwatch.com/issues/ba620b24-4a16-45ba-8907-4fb454d4120b","cveId":"CVE-2023-43472","title":"CVE-2023-43472: An issue in MLFlow versions 2.8.1 and before allows a remote attacker to obtain sensitive information via a crafted…","headline":"MLFlow information disclosure through crafted REST API request","severity":"high","publishedAt":"2023-12-05T12:15:07.667Z","affected":["mlflow@< 2.9.0 (fixed: 2.9.0)"],"epssScore":0.36582,"matchedBy":"ecosystem"},{"id":"5fad1204-085a-4aec-a785-c8d5dce616ab","url":"https://aisecwatch.com/issues/5fad1204-085a-4aec-a785-c8d5dce616ab","cveId":"CVE-2023-6014","title":"CVE-2023-6014: An attacker is able to arbitrarily create an account in MLflow bypassing any authentication requirment.","headline":"MLflow authentication bypass allows arbitrary account creation","severity":"critical","publishedAt":"2023-11-17T02:15:09.267Z","affected":["mlflow@< 2.8.0 (fixed: 2.8.0)"],"epssScore":0.01167,"matchedBy":"ecosystem"},{"id":"a08cf275-eb12-4655-aaf0-748a9315c938","url":"https://aisecwatch.com/issues/a08cf275-eb12-4655-aaf0-748a9315c938","cveId":"CVE-2023-6018","title":"CVE-2023-6018: An attacker can overwrite any file on the server hosting MLflow without any authentication.","headline":"MLflow arbitrary file overwrite without authentication","severity":"critical","publishedAt":"2023-11-16T21:15:34.880Z","affected":["mlflow@<= 2.8.1 (fixed: 2.9.2)"],"epssScore":0.47874,"matchedBy":"ecosystem"},{"id":"d4edb1d5-1aa5-4a8f-b87b-14835a8eb0f7","url":"https://aisecwatch.com/issues/d4edb1d5-1aa5-4a8f-b87b-14835a8eb0f7","cveId":"CVE-2023-6015","title":"CVE-2023-6015: MLflow allowed arbitrary files to be PUT onto the server.","headline":null,"severity":"high","publishedAt":"2023-11-16T21:15:34.370Z","affected":["mlflow@< 2.8.1 (fixed: 2.8.1)"],"epssScore":0.04444,"matchedBy":"ecosystem"},{"id":"494cc40c-a6f3-4afd-b270-c08f212d2f23","url":"https://aisecwatch.com/issues/494cc40c-a6f3-4afd-b270-c08f212d2f23","cveId":"CVE-2023-4033","title":"CVE-2023-4033: OS Command Injection in GitHub repository mlflow/mlflow prior to 2.6.0.","headline":"mlflow/mlflow OS command injection in GitHub repository","severity":"high","publishedAt":"2023-08-01T05:15:10.913Z","affected":["mlflow@< 2.6.0 (fixed: 2.6.0)"],"epssScore":0.01253,"matchedBy":"ecosystem"},{"id":"7da3be13-89c1-42b1-a760-758069d6e191","url":"https://aisecwatch.com/issues/7da3be13-89c1-42b1-a760-758069d6e191","cveId":"CVE-2023-3765","title":"CVE-2023-3765: Absolute Path Traversal in GitHub repository mlflow/mlflow prior to 2.5.0.","headline":"mlflow/mlflow absolute path traversal","severity":"critical","publishedAt":"2023-07-19T05:15:10.847Z","affected":["mlflow@< 2.5.0 (fixed: 2.5.0)"],"epssScore":0.6755,"matchedBy":"ecosystem"},{"id":"c39bc197-4a59-4f65-a516-12e5d13aed32","url":"https://aisecwatch.com/issues/c39bc197-4a59-4f65-a516-12e5d13aed32","cveId":"CVE-2023-2780","title":"CVE-2023-2780: Path Traversal: '\\..\\filename' in GitHub repository mlflow/mlflow prior to 2.3.1.","headline":"mlflow path traversal via crafted filename using backslash sequences","severity":"critical","publishedAt":"2023-05-18T01:15:09.470Z","affected":["mlflow@< 2.3.0 (fixed: 2.3.0)"],"epssScore":0.06363,"matchedBy":"ecosystem"},{"id":"280d16da-e37f-48ef-909e-bcdc4d0186fc","url":"https://aisecwatch.com/issues/280d16da-e37f-48ef-909e-bcdc4d0186fc","cveId":"CVE-2023-30172","title":"CVE-2023-30172: A directory traversal vulnerability in the /get-artifact API method of the mlflow platform up to v2.0.1 allows…","headline":"mlflow directory traversal in /get-artifact API method","severity":"high","publishedAt":"2023-05-11T06:15:08.880Z","affected":["mlflow@< 2.0.0rc0 (fixed: 2.0.0rc0)"],"epssScore":0.01005,"matchedBy":"ecosystem"},{"id":"8c35ad84-87cf-46fe-b5a4-bd7e4baa787f","url":"https://aisecwatch.com/issues/8c35ad84-87cf-46fe-b5a4-bd7e4baa787f","cveId":"CVE-2023-2356","title":"CVE-2023-2356: Relative Path Traversal in GitHub repository mlflow/mlflow prior to 2.3.1.","headline":"mlflow/mlflow relative path traversal in GitHub repository","severity":"high","publishedAt":"2023-04-28T04:15:08.890Z","affected":["mlflow@< 2.3.1 (fixed: 2.3.1)"],"epssScore":0.04153,"matchedBy":"ecosystem"},{"id":"ba3ac010-5c74-4c0c-9f57-d001ad360b7a","url":"https://aisecwatch.com/issues/ba3ac010-5c74-4c0c-9f57-d001ad360b7a","cveId":"CVE-2023-1177","title":"CVE-2023-1177: Path Traversal: '\\..\\filename' in GitHub repository mlflow/mlflow prior to 2.2.1.\n\n","headline":"mlflow path traversal via crafted filename","severity":"critical","publishedAt":"2023-03-24T19:15:10.193Z","affected":["mlflow@<= 2.2.0 (fixed: 2.2.1)"],"epssScore":0.6968,"matchedBy":"ecosystem"},{"id":"5e1eb6e5-cdf1-435a-92bd-79cc67e2e19f","url":"https://aisecwatch.com/issues/5e1eb6e5-cdf1-435a-92bd-79cc67e2e19f","cveId":"CVE-2023-1176","title":"CVE-2023-1176: Absolute Path Traversal in GitHub repository mlflow/mlflow prior to 2.2.2.","headline":"mlflow/mlflow absolute path traversal","severity":"low","publishedAt":"2023-03-24T19:15:10.110Z","affected":["mlflow@<= 2.2.0 (fixed: 2.2.1)"],"epssScore":0.00583,"matchedBy":"ecosystem"},{"id":"31ea2fa8-d4f8-4508-af9e-4d47838ed517","url":"https://aisecwatch.com/issues/31ea2fa8-d4f8-4508-af9e-4d47838ed517","cveId":"CVE-2022-0736","title":"CVE-2022-0736: Insecure Temporary File in GitHub repository mlflow/mlflow prior to 1.23.1.","headline":"mlflow/mlflow insecure temporary file","severity":"high","publishedAt":"2022-02-23T14:15:14.420Z","affected":["mlflow@< 1.23.1 (fixed: 1.23.1)"],"epssScore":0.01575,"matchedBy":"ecosystem"}],"checkedAt":"2026-10-09T21:58:13.405Z"},"meta":{"advisoryMatching":"by package name and ecosystem; an advisory with no ecosystem recorded for the package is matched by name alone"}}