© 2025-2026 PySpect
First version without a known vulnerability: 3.15.0
MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding)
Fixed in: 3.15.0
MLflow: trace API endpoints lack proper authorization validators
Fixed in: 3.13.0rc0
MLflow: Deterministic sampling in dataset digest enables predictable collisions
Fixed in: 3.10.1
MLflow: Environment variable injection in AI Gateway secrets enables server-side credential exfiltration
Fixed in: 3.11.0
MLflow: Any authenticated user can enumerate all gateway secrets, endpoints, and model definitions
Fixed in: 3.11.0rc0
MLflow allows unauthorized access to multipart upload endpoints when the `--serve-artifacts` mode is enabled
Fixed in: 3.11.0rc1, 3.11.0rc0
MLflow authenticated users can enumerate any registered model versions due to lack of per-model permissions checks
Fixed in: 3.10.0
MLflow: Improper Origin Validation in MLflow Assistant /ajax-api Endpoints Enables Browser-Mediated Local Command Execution
Fixed in: 3.10.0
MLFlow Creates a Temporary File With Insecure Permissions
Fixed in: 3.11.0
MLflow: unauthenticated access to certain FastAPI routes
Fixed in: 3.11.0, 3.10.0
MLflow allows an unauthenticated remote attacker to read arbitrary files from the server's filesystem
Fixed in: 3.10.0
MLflow Has a Server-Side Request Forgery (SSRF) Vulnerability
Fixed in: 3.9.0
MLflow is vulnerable to an authorization bypass affecting the AJAX endpoint
Fixed in: 3.11.0rc0
MLflow is vulnerable to Stored Cross-Site Scripting (XSS) caused by unsafe parsing of YAML-based MLmodel artifacts in its web interface
Fixed in: 3.11.1, 3.11.0rc0
mlflow: FastAPI job endpoints under `/ajax-api/3.0/jobs/*` are not protected by authentication or authorization
Mlflow: Command Injection when serving models with enable_mlserver=True
Fixed in: 3.9.0
MLflow Command Injection vulnerability
Fixed in: 3.8.1
MLFlow path traversal vulnerability
Fixed in: 3.9.0rc0
MLFlow allows Tracing + Assessments Access
Arbitrary file write via tar traversal in mlflow
Fixed in: 3.9.0rc0
MLflow has a command injection in mlflow/sagemaker/__init__.py
Fixed in: 3.8.0rc0
MLflow Use of Default Password Authentication Bypass Vulnerability
Fixed in: 3.8.0rc0
MLflow Tracking Server Artifact Handler Directory Traversal Remote Code Execution Vulnerability
Fixed in: 3.8.0rc0
mlflow Creates of Temporary File in Directory with Insecure Permissions
Fixed in: 3.4.0rc0
MLFlow is vulnerable to DNS rebinding attacks due to a lack of Origin header validation
Fixed in: 3.5.0
MLflow Tracking Server Model Creation Directory Traversal Remote Code Execution Vulnerability
Fixed in: 3.0.0, 2.22.4
MLflow Weak Password Requirements Authentication Bypass Vulnerability
Fixed in: 2.22.0rc0
MLFlow SSRF via gateway_proxy_handler
Fixed in: 3.1.0, 2.22.2, 39a419b4ec8fd11b59b3e50ab397042a490f2324
MLflow has Weak Password Requirements
Fixed in: 2.19.0, 149c9e18aa219bc47e86b432e130e467a36f4a17
MLflow Cross-Site Request Forgery (CSRF) vulnerability
Fixed in: 2.20.3
MLflow Uncontrolled Resource Consumption vulnerability
MLflow has a Local File Read/Path Traversal in dbfs
Fixed in: 2.17.0rc0
MLflow Uncontrolled Resource Consumption vulnerability
MLflow's excessive directory permissions allow local privilege escalation
Fixed in: 2.16.0
Undefined Behavior in mlflow
Fixed in: 2.11.3
Local File Inclusion in mlflow
Fixed in: 2.11.3, 96f0b573a73d8eedd6735a2ce26e08859527be07
Remote code execution in mlflow
Fixed in: 2.9.0, 400c226953b4568f4361bc0a0c223511652c2b9d
MLFlow unsafe deserialization
MLFlow unsafe deserialization
MLFlow unsafe deserialization
MLFlow improper input validation
MLFlow unsafe deserialization
MLFlow unsafe deserialization
MLFlow unsafe deserialization
MLFlow unsafe deserialization
MLFlow unsafe deserialization
MLFlow unsafe deserialization
MLflow allows low privilege users to delete any artifact
Fixed in: 2.10.1, b43e0e3de5b500554e13dc032ba2083b2d6c94b8
MLflow has a Local File Read/Path Traversal bypass
Fixed in: 2.12.1, f8d51e21523238280ebcfdb378612afd7844eca8
mlflow vulnerable to Path Traversal
Fixed in: 2.10.0, 438a450714a3ca06285eeea34bdc6cf79d7f6cbc
mlflow vulnerable to Path Traversal
mlflow vulnerable to Path Traversal
mlflow vulnerable to Path Traversal
Fixed in: 2.12.1
mlflow vulnerable to Path Traversal
mlflow Path Traversal vulnerability
Fixed in: 2.12.1
MLFlow Cross-site Scripting vulnerability leads to client-side Remote Code Execution
Fixed in: 2.10.0
Cross-site Scripting in MLFlow
Fixed in: 2.10.0
MLflow Server-Side Request Forgery (SSRF)
Fixed in: 2.9.2
MLflow Path Traversal Vulnerability
Fixed in: 2.9.2, 1da75dfcecd4d169e34809ade55748384e8af6c1
MLFlow Path Traversal Vulnerability
Fixed in: 2.9.2
MLflow Local File Disclosure Vulnerability
Fixed in: 2.9.2
MLflow Path Traversal Vulnerability
Fixed in: 2.9.2
mlflow Command Injection vulnerability
Fixed in: 2.9.2
Path traversal in MLflow
Fixed in: 2.9.2, 1da75dfcecd4d169e34809ade55748384e8af6c1
Path traversal in MLflow
Fixed in: 2.9.2, 1c6309f884798fbf56017a3cc808016869ee8de4
Jinja2 template injection in mlflow
Fixed in: 2.9.2, 432b8ccf27fd3a76df4ba79bb1bec62118a85625
Cross-site Scripting (XSS) in MLflow
Fixed in: 2.9.0, 28ff3f94994941e038f2172c6484b65dc4db6ca1, 2.9.1
Information exposure in MLflow
Fixed in: 2.9.0
MLflow authentication requirement bypass can allow a user to arbitrarily create an account
Fixed in: 2.8.0
Remote Code Execution due to Full Controled File Write in mlflow
Fixed in: 2.9.2
MLflow allowed arbitrary files to be PUT onto the server
Fixed in: 2.8.1
mlflow vulnerable to OS Command Injection
Fixed in: 2.6.0, 6dde93758d42455cb90ef324407919ed67668b9b
MLflow Path Traversal vulnerability
Fixed in: 2.5.0, 6dde93758d42455cb90ef324407919ed67668b9b
mlflow Path Traversal vulnerability
Fixed in: 2.3.0, fae77a525dd908c56d6204a4cef1c1c75b4e9857, 2.3.1
mflow vulnerable to directory traversal
Fixed in: 2.0.0rc0, 2.0.1
Remote file access vulnerability in `mlflow server` and `mlflow ui` CLIs
Fixed in: 2.3.1
Relative path traversal in mlflow
Fixed in: 2.3.1, f73147496e05c09a8b83d95fb4f1bf86696c6342
Remote file existence check vulnerability in `mlflow server` and `mlflow ui` CLIs
Fixed in: 2.2.1, 63ef72aa4334a6473ce7f889573c92fcae0b3c0d, 2.2.2
mlflow is vulnerable to remote file access in `mlflow server` and `mlflow ui` CLIs
Fixed in: 2.2.1, 7162a50c654792c21f3e4a160eb1a0e6a34f6e6e
Insecure Temporary File in mlflow
Fixed in: 1.23.1, 61984e6843d2e59235d82a580c529920cd8f3711