VendorsLF Projectsmlflowall versions
Vulnerabilities

LF Projects MLflow

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

77CVEs
CVE-2023-3765
Absolute Path Traversal in mlflow/mlflow
Published 2023-07-19 · Modified
10.0EPSS 0.676
CVE-2023-6018
MLflow Arbitrary File Write
Published 2023-11-16 · Modified
10.0EPSS 0.479
CVE-2023-6015
MLflow Arbitrary File Upload
Published 2023-11-16 · Modified
10.0EPSS 0.044
CVE-2023-2356
Relative Path Traversal in mlflow/mlflow
Published 2023-04-28 · Modified
10.0EPSS 0.042
CVE-2023-6977
Path Traversal: '\..\filename'
Published 2023-12-20 · Modified
10.0EPSS 0.039
CVE-2024-0520
Remote Code Execution due to Full Controlled File Write in mlflow/mlflow
Published 2024-06-06 · Modified
10.0EPSS 0.024
CVE-2025-15379
Command Injection in mlflow/mlflow
Published 2026-03-30 · Analyzed
10.0EPSS 0.024
CVE-2023-6709
Improper Neutralization of Special Elements Used in a Template Engine in mlflow/mlflow
Published 2023-12-12 · Modified
10.0EPSS 0.009
CVE-2025-15036
Path Traversal Vulnerability in mlflow/mlflow
Published 2026-03-30 · Modified
10.0EPSS 0.006
CVE-2023-1177
Path Traversal: '\..\filename' in mlflow/mlflow
Published 2023-03-24 · Modified
9.8EPSS 0.697
CVE-2025-11201
MLflow Tracking Server Model Creation Directory Traversal Remote Code Execution Vulnerability
Published 2025-10-29 · Analyzed
9.8EPSS 0.270
CVE-2023-2780
Path Traversal: '\..\filename' in mlflow/mlflow
Published 2023-05-17 · Modified
9.8EPSS 0.064
CVE-2026-0545
Missing Authentication for Critical Function in mlflow/mlflow
Published 2026-04-03 · Modified
9.8EPSS 0.044
CVE-2023-6975
Path Traversal: '\..\filename'
Published 2023-12-20 · Modified
9.8EPSS 0.020
CVE-2023-6974
Server-Side Request Forgery (SSRF)
Published 2023-12-20 · Modified
9.8EPSS 0.015
CVE-2025-11200
MLflow Weak Password Requirements Authentication Bypass Vulnerability
Published 2025-10-29 · Analyzed
9.8EPSS 0.015
CVE-2023-6014
MLflow Authentication Bypass
Published 2023-11-16 · Modified
9.8EPSS 0.012
CVE-2026-0596
Command Injection in mlflow/mlflow
Published 2026-03-31 · Analyzed
9.6EPSS 0.013
CVE-2023-6753
Path Traversal in mlflow/mlflow
Published 2023-12-13 · Modified
9.6EPSS 0.011
CVE-2024-27132
Insufficient sanitization in MLflow leads to XSS when running an untrusted recipe.
Published 2024-02-23 · Analyzed
9.6EPSS 0.009
CVE-2024-27133
Insufficient sanitization in MLflow leads to XSS when running a recipe that uses an untrusted dataset.
Published 2024-02-23 · Analyzed
9.6EPSS 0.007
CVE-2026-2611
Improper Origin Validation in mlflow/mlflow
Published 2026-05-19 · Modified
9.6EPSS 0.004
CVE-2026-64849
MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding)
Published 2026-08-17 · Analyzed
9.3KEVEPSS 0.164
CVE-2024-3573
Local File Inclusion (LFI) via Scheme Confusion in mlflow/mlflow
Published 2024-04-16 · Analyzed
9.3EPSS 0.007
CVE-2025-15031
Path Traversal Vulnerability in mlflow/mlflow
Published 2026-03-18 · Modified
9.1EPSS 0.009
CVE-2026-4035
Environment Variable Resolution Vulnerability in mlflow/mlflow
Published 2026-06-03 · Modified
9.1EPSS 0.005
CVE-2023-6940
Command Injection
Published 2023-12-19 · Modified
9.0EPSS 0.012
CVE-2026-2651
Missing Authorization Validation in mlflow/mlflow
Published 2026-05-25 · Modified
9.0EPSS 0.003
CVE-2025-14287
Command Injection in mlflow/mlflow
Published 2026-03-15 · Modified
8.8EPSS 0.015
CVE-2023-4033
OS Command Injection in mlflow/mlflow
Published 2023-08-01 · Modified
8.8EPSS 0.013
CVE-2023-6976
Unrestricted Upload of File with Dangerous Type
Published 2023-12-20 · Modified
8.8EPSS 0.010
CVE-2024-37061
Remote Code Execution can occur in versions of the MLflow platform running version 1.11.0 or newer, enabling a maliciously crafted MLproject to execute arbitrary code on an end user’s system when run.
Published 2024-06-04 · Analyzed
8.8EPSS 0.009
CVE-2024-37060
Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.27.0 or newer, enabling a maliciously crafted Recipe to execute arbitrary code on an end user’s system when run.
Published 2024-06-04 · Analyzed
8.8EPSS 0.008
CVE-2024-37054
Deserialization of untrusted data can occur in versions of the MLflow platform running version 0.9.0 or newer, enabling a maliciously uploaded PyFunc model to run arbitrary code on an end user’s system when interacted with.
Published 2024-06-04 · Analyzed
8.8EPSS 0.007
CVE-2024-37052
Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.1.0 or newer, enabling a maliciously uploaded scikit-learn model to run arbitrary code on an end user’s system when interacted with.
Published 2024-06-04 · Analyzed
8.8EPSS 0.006
CVE-2024-37055
Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.24.0 or newer, enabling a maliciously uploaded pmdarima model to run arbitrary code on an end user’s system when interacted with.
Published 2024-06-04 · Analyzed
8.8EPSS 0.006
CVE-2024-37053
Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.1.0 or newer, enabling a maliciously uploaded scikit-learn model to run arbitrary code on an end user’s system when interacted with.
Published 2024-06-04 · Analyzed
8.8EPSS 0.006
CVE-2024-37056
Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.23.0 or newer, enabling a maliciously uploaded LightGBM scikit-learn model to run arbitrary code on an end user’s system when interacted with.
Published 2024-06-04 · Analyzed
8.8EPSS 0.006
CVE-2024-37057
Deserialization of untrusted data can occur in versions of the MLflow platform running version 2.0.0rc0 or newer, enabling a maliciously uploaded Tensorflow model to run arbitrary code on an end user’s system when interacted with.
Published 2024-06-04 · Analyzed
8.8EPSS 0.006
CVE-2024-37058
Deserialization of untrusted data can occur in versions of the MLflow platform running version 2.5.0 or newer, enabling a maliciously uploaded Langchain AgentExecutor model to run arbitrary code on an end user’s system when interacted with.
Published 2024-06-04 · Analyzed
8.8EPSS 0.006
1 / 2Next →