Lfprojects Mlflow Vulnerabilities

4 advisories affecting Lfprojects Mlflow

4

Total CVEs

3

Critical

1

High

CVE-2026-64849

Aug 17, 2026

Critical 9.3

MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. Prior to 3.15.0, the unauthenticated POST /api/2.0/mlflow/webhooks/{id}/test endpoint c...

Read Advisory

CVE-2025-15036

Mar 30, 2026

Critical 9.6

A path traversal vulnerability exists in the `extract_archive_to_dir` function within the `mlflow/pyfunc/dbconnect_artifact_cache.py` file of the mlflow/mlflow repository. This vulnerability, present ...

Read Advisory

CVE-2025-15379

Mar 30, 2026

Critical 10.0

A command injection vulnerability exists in MLflow's model serving container initialization code, specifically in the `_install_model_dependencies_to_env()` function. When deploying a model with `env_...

Read Advisory

CVE-2025-15031

Mar 18, 2026

High 8.1

A vulnerability in MLflow's pyfunc extraction process allows for arbitrary file writes due to improper handling of tar archive entries. Specifically, the use of `tarfile.extractall` without path valid...

Read Advisory

Never Miss a Critical Alert

CVE advisories, breach reports, and threat intel — delivered daily to your inbox.