Known Vulnerabilities for Mlflow by Lfprojects
Listed below are 8 of the newest known vulnerabilities associated with "Mlflow" by "Lfprojects".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-33866 json | MLflow is vulnerable to an authorization bypass affecting the AJAX endpoint used to download saved model artifacts. Due to mi... | Not Provided | 2026-04-07 | 2026-04-09 |
| CVE-2026-33865 json | MLflow is vulnerable to Stored Cross-Site Scripting (XSS) caused by unsafe parsing of YAML-based MLmodel artifacts in its web... | Not Provided | 2026-04-07 | 2026-04-09 |
| CVE-2026-0596 json | A command injection vulnerability exists in mlflow/mlflow when serving a model with `enable_mlserver=True`. The `model_uri` i... | Not Provided | 2026-03-31 | 2026-04-01 |
| CVE-2026-0545 json | In mlflow/mlflow, the FastAPI job endpoints under `/ajax-api/3.0/jobs/*` are not protected by authentication or authorization... | Not Provided | 2026-04-03 | 2026-04-03 |
| CVE-2025-15381 json | In the latest version of mlflow/mlflow, when the `basic-auth` app is enabled, tracing and assessment endpoints are not protec... | Not Provided | 2026-03-27 | 2026-03-28 |
| CVE-2025-15379 json | A command injection vulnerability exists in MLflow's model serving container initialization code, specifically in the `_insta... | Not Provided | 2026-03-30 | 2026-03-31 |
| CVE-2025-15036 json | A path traversal vulnerability exists in the `extract_archive_to_dir` function within the `mlflow/pyfunc/dbconnect_artifact_c... | Not Provided | 2026-03-30 | 2026-03-31 |
| CVE-2023-30172 json | A directory traversal vulnerability in the /get-artifact API method of the mlflow platform up to v2.0.1 allows attackers to r... | 7.5 - HIGH | 2023-05-11 | 2023-05-22 |
| CVE-2023-4033 json | OS Command Injection in GitHub repository mlflow/mlflow prior to 2.6.0. | 7.8 - HIGH | 2023-08-01 | 2023-08-04 |
| CVE-2023-3765 json | Absolute Path Traversal in GitHub repository mlflow/mlflow prior to 2.5.0. | 10 - CRITICAL | 2023-07-19 | 2023-07-28 |