CVE-2024-45853 is a vulnerability in MindsDB (a platform for building AI applications) versions 23.10.2.0 and newer where deserialization of untrusted data (the process of converting received data back into usable objects without checking if it's safe) allows an attacker to upload a malicious model that runs arbitrary code on the server when making predictions. This is a serious flaw because it gives attackers full control to execute whatever commands they want on the affected system.
7.1(high)
EPSS: 0.2%
CVE-2024-37052: Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.1.0 or newer, enabling
Model Stability Defense Against Model Poisoning in Federated Learning
GDetox: Purifying Backdoor Encoder in Graph Self-Supervised Learning via Knowledge Distillation
CVE-2024-37058: Deserialization of untrusted data can occur in versions of the MLflow platform running version 2.5.0 or newer, enabling
Versatile Backdoor Attack With Visible, Semantic, Sample-Specific and Compatible Triggers
Original source: https://nvd.nist.gov/vuln/detail/CVE-2024-45853
First tracked: February 15, 2026 at 08:53 PM
Classified by LLM (prompt v3) · confidence: 92%