CRITICAL10.0CVE-2025-15036Path Traversal Vulnerability in mlflow/mlflow from 0, < 3.9.0
CRITICAL10.0CVE-2024-0520Remote Code Execution due to Full Controlled File Write in mlflow/mlflow from 0, < 2.9.1
CRITICAL10.0CVE-2023-6831Path Traversal: '\..\filename' in mlflow/mlflow from 0, < 2.9.2
CRITICAL10.0Absolute Path Traversal in mlflow/mlflow
from 0, < 2.5.0
CRITICAL10.0Relative Path Traversal in mlflow/mlflow
from 0, < 2.3.1
CRITICAL9.8Command Injection in mlflow/mlflow
>= 3.8.0, < 3.9.0
CRITICAL9.8MLflow Weak Password Requirements Authentication Bypass Vulnerability
from 0, < 2.21.1
CRITICAL9.8MLflow Tracking Server Model Creation Directory Traversal Remote Code Execution Vulnerability
from 0, < 3.0.0
CRITICAL9.8Path Traversal: '\..\filename' in mlflow/mlflow
from 0, < 2.3.1
CRITICAL9.8Path Traversal: '\..\filename' in mlflow/mlflow
from 0, < 2.2.1
CRITICAL9.6Insufficient sanitization in MLflow leads to XSS when running an untrusted recipe.
from 0, < 2.10.0
CRITICAL9.6Insufficient sanitization in MLflow leads to XSS when running a recipe that uses an untrusted dataset.
from 0, < 2.10.0
CRITICAL9.3Local File Inclusion (LFI) via Scheme Confusion in mlflow/mlflow
from 0, < 2.10.0
HIGH8.8MLFlow unsafe deserialization
>= 2.0.0, <= 2.13.1
HIGH8.8MLFlow unsafe deserialization
>= 2.5.0, < 2.13.2
HIGH8.8MLFlow unsafe deserialization
>= 0.5.0, < 2.13.2
HIGH8.8MLFlow unsafe deserialization
>= 1.27.0, < 2.13.2
HIGH8.8MLFlow improper input validation
>= 1.11.0, < 2.13.2
HIGH8.8MLFlow unsafe deserialization
>= 1.1.0, < 2.13.2
HIGH8.8MLFlow unsafe deserialization
>= 1.1.0, < 2.13.2
HIGH8.8MLFlow unsafe deserialization
>= 0.9.0, < 2.13.2
HIGH8.8MLFlow unsafe deserialization
>= 1.24.0, < 2.13.2
HIGH8.8MLFlow unsafe deserialization
>= 1.23.0, < 2.13.2
HIGH8.8Unrestricted Upload of File with Dangerous Type
from 0, < 2.9.2
HIGH8.8Command Injection
from 0, < 2.9.2
HIGH8.8Path Traversal in mlflow/mlflow
from 0, < 2.9.2
HIGH8.8Improper Neutralization of Special Elements Used in a Template Engine in mlflow/mlflow
from 0, < 2.9.2
HIGH8.8OS Command Injection in mlflow/mlflow
from 0, < 2.6.0
HIGH8.2Insecure Temporary File in mlflow/mlflow
from 0, < 1.23.1
HIGH8.1Authorization Bypass in mlflow/mlflow
from 0, < 3.14.0
HIGH8.1Path Traversal Vulnerability in mlflow/mlflow
from 0, < 3.11.1
HIGH8.1DNS Rebinding Vulnerability in mlflow/mlflow
from 0, < 3.5.0
HIGH8.1Path Traversal Vulnerability in mlflow/mlflow
from 0, < 2.12.2
HIGH7.5Arbitrary File Read via Prompt Tag Source Validation Bypass in mlflow/mlflow
from 0, < 3.10.0
HIGH7.5Command Injection in mlflow/mlflow
from 0, < 3.7.0
HIGH7.5Denial of Service through Batched Queries in GraphQL in mlflow/mlflow
>= 2.17.2, < 2.18.0
HIGH7.5Path Traversal in mlflow/mlflow
>= 2.15.1, < 2.16.0
HIGH7.5Local File Inclusion (LFI) via URI Fragment Parsing in mlflow/mlflow
from 0, < 2.11.3
HIGH7.5Path Traversal Bypass in mlflow/mlflow
from 0, < 2.12.1
HIGH7.5Path Traversal Vulnerability in mlflow/mlflow
from 0, < 2.12.1
HIGH7.5Path Traversal via Parameter Smuggling in mlflow/mlflow
from 0, < 2.11.3
HIGH7.5Local File Read via Path Traversal in mlflow/mlflow
from 0, < 2.11.3
HIGH7.5Path Traversal Vulnerability in mlflow/mlflow
from 0, < 2.12.1
HIGH7.5Path Traversal: '\..\filename' in mlflow/mlflow
from 0, < 2.9.2
HIGH7.5Path Traversal: '\..\filename'
>= 1.0.0, < 2.9.2
HIGH7.5Information exposure in MLflow
from 0, < 2.8.2
HIGH7.5mflow vulnerable to directory traversal
from 0, < 2.0.1
HIGH7.1CSRF in mlflow/mlflow
>= 2.17.0, < 2.20.1
HIGH7.0Incomplete Fix for CVE-2025-10279: Insecure Temporary Directory Permissions in mlflow/mlflow
from 0, < 3.11.0
HIGH7.0Privilege Escalation in mlflow/mlflow
from 0, < 3.4.0
HIGH7.0Excessive directory permissions in MLflow leads to local privilege escalation when using spark_udf
from 0, < 2.16.0
MEDIUM6.5Improper Access Control in mlflow/mlflow
>= 3.9.0, < 3.10.0
MEDIUM6.5Authorization Bypass in SearchModelVersions in mlflow/mlflow
from 0, < 3.10.0
MEDIUM6.5Reflected XSS via Content-Type Header in mlflow/mlflow
from 0, < 2.9.1
MEDIUM5.8MLFlow SSRF via gateway_proxy_handler
from 0, < 3.1.0
MEDIUM5.4Stored XSS via unsafe YAML parsing in MLflow
from 0, < 3.11.1
MEDIUM5.4Undefined Behavior in mlflow
MEDIUM5.4Improper Access Control in mlflow/mlflow
from 0, < 2.12.1
MEDIUM5.3Uncontrolled Resource Consumption in mlflow/mlflow
>= 2.13.2, < 2.14.0
MEDIUM4.3Authorization Bypass in MLflow AJAX Endpoint
from 0, < 3.11.1
LOW3.8Weak Password Requirements in mlflow/mlflow
from 0, < 2.19.0
LOW3.6MLflow Dataset Digest Computation digest_utils.py mlflow.data.digest_utils weak hash
from 0, < 3.10.1
LOW3.3Absolute Path Traversal in mlflow/mlflow
from 0, < 2.2.2
—MLflow Experiment-scoped Label Schema CRUD API authorization
from 0, < 3.13.0