Launch Week Day 1: Announcing Security Design Review
100 Total advisories
100 Vulnerabilities
0 Malware

Vulnerabilities

MEDIUM 6.5
PyPI

CVE-2026-2734

MLflow authenticated users can enumerate any registered model versions due to lack of per-model permissions checks

MEDIUM 4.3
PyPI

CVE-2026-33866

CVE-2026-33866

UNKNOWN
PyPI

CVE-2025-52967

CVE-2025-52967

MEDIUM 5.4
PyPI

CVE-2026-33865

CVE-2026-33865

HIGH 7.8
PyPI

CVE-2023-4033

CVE-2023-4033

HIGH 7.0
PyPI

CVE-2024-27134

CVE-2024-27134

UNKNOWN
PyPI

CVE-2023-2356

CVE-2023-2356

UNKNOWN
PyPI

CVE-2023-30172

CVE-2023-30172

UNKNOWN
PyPI

CVE-2023-2780

CVE-2023-2780

UNKNOWN
PyPI

CVE-2023-1176

CVE-2023-1176

MEDIUM 6.1
PyPI

CVE-2023-6568

CVE-2023-6568

HIGH 8.1
PyPI

CVE-2023-6831

CVE-2023-6831

HIGH 7.5
PyPI

CVE-2023-6909

CVE-2023-6909

HIGH 8.8
PyPI

CVE-2023-6753

CVE-2023-6753

HIGH 7.5
PyPI

CVE-2024-3848

CVE-2024-3848

CRITICAL 10.0
PyPI

CVE-2023-3765

CVE-2023-3765

HIGH 8.8
PyPI

CVE-2023-6709

CVE-2023-6709

UNKNOWN
PyPI

CVE-2023-1177

CVE-2023-1177

UNKNOWN
PyPI

CVE-2024-4263

CVE-2024-4263

CRITICAL 9.3
PyPI

CVE-2024-3573

CVE-2024-3573

HIGH 7.5
PyPI

CVE-2024-2928

CVE-2024-2928

CRITICAL 9.6
PyPI

CVE-2024-27133

CVE-2024-27133

CRITICAL 9.6
PyPI

CVE-2024-27132

CVE-2024-27132

HIGH 8.8
PyPI

CVE-2024-0520

CVE-2024-0520

MEDIUM 5.5
PyPI

CVE-2025-1474

CVE-2025-1474

MEDIUM 4.3
PyPI

CVE-2026-33866

MLflow is vulnerable to an authorization bypass affecting the AJAX endpoint

MEDIUM 5.4
PyPI

CVE-2026-33865

MLflow is vulnerable to Stored Cross-Site Scripting (XSS) caused by unsafe parsing of YAML-based MLmodel artifacts in its web interface

UNKNOWN
PyPI

CVE-2026-10803

CVE-2026-10803

HIGH 7.0
PyPI

CVE-2026-4137

MLFlow Creates a Temporary File With Insecure Permissions

CRITICAL 9.6
PyPI

CVE-2026-2611

MLflow: Improper Origin Validation in MLflow Assistant /ajax-api Endpoints Enables Browser-Mediated Local Command Execution

HIGH 7.1
PyPI

CVE-2026-2393

MLflow Has a Server-Side Request Forgery (SSRF) Vulnerability

HIGH 7.5
PyPI

CVE-2026-2614

MLflow allows an unauthenticated remote attacker to read arbitrary files from the server's filesystem

HIGH 8.6
PyPI

CVE-2026-2652

MLflow: unauthenticated access to certain FastAPI routes

CRITICAL 9.6
PyPI

CVE-2026-0596

Mlflow: Command Injection when serving models with enable_mlserver=True

CRITICAL 9.6
PyPI

CVE-2025-15036

MLFlow path traversal vulnerability

CRITICAL 10.0
PyPI

CVE-2025-15379

MLflow Command Injection vulnerability

HIGH 7.5
PyPI

CVE-2025-14287

MLflow has a command injection in mlflow/sagemaker/__init__.py

HIGH 8.1
PyPI

CVE-2025-14279

MLFlow is vulnerable to DNS rebinding attacks due to a lack of Origin header validation

HIGH 7.0
PyPI

CVE-2025-10279

mlflow Creates of Temporary File in Directory with Insecure Permissions

CRITICAL 9.1
PyPI

CVE-2026-0545

mlflow: FastAPI job endpoints under `/ajax-api/3.0/jobs/*` are not protected by authentication or authorization

HIGH 8.1
PyPI

CVE-2025-15381

MLFlow allows Tracing + Assessments Access

HIGH 8.1
PyPI

CVE-2025-15031

Arbitrary file write via tar traversal in mlflow

HIGH 8.1
PyPI

CVE-2026-2033

MLflow Tracking Server Artifact Handler Directory Traversal Remote Code Execution Vulnerability

CRITICAL 9.8
PyPI

CVE-2026-2635

MLflow Use of Default Password Authentication Bypass Vulnerability

MEDIUM 5.4
PyPI

CVE-2024-4263

MLflow allows low privilege users to delete any artifact

CRITICAL 9.8
PyPI

CVE-2023-1177

mlflow is vulnerable to remote file access in `mlflow server` and `mlflow ui` CLIs

HIGH 8.8
PyPI

CVE-2024-37061

MLFlow improper input validation

HIGH 8.8
PyPI

CVE-2024-37057

MLFlow unsafe deserialization

HIGH 8.8
PyPI

CVE-2024-37055

MLFlow unsafe deserialization

HIGH 8.8
PyPI

CVE-2024-37054

MLFlow unsafe deserialization

HIGH 8.8
PyPI

CVE-2024-37052

MLFlow unsafe deserialization

HIGH 8.8
PyPI

CVE-2024-37058

MLFlow unsafe deserialization

HIGH 8.8
PyPI

CVE-2024-37060

MLFlow unsafe deserialization

HIGH 8.8
PyPI

CVE-2024-37056

MLFlow unsafe deserialization

HIGH 8.8
PyPI

CVE-2024-37059

MLFlow unsafe deserialization

HIGH 8.8
PyPI

CVE-2024-37053

MLFlow unsafe deserialization

HIGH 8.1
PyPI

CVE-2025-11201

MLflow Tracking Server Model Creation Directory Traversal Remote Code Execution Vulnerability

HIGH 8.1
PyPI

CVE-2025-11200

MLflow Weak Password Requirements Authentication Bypass Vulnerability

MEDIUM 5.9
PyPI

CVE-2025-0453

MLflow Uncontrolled Resource Consumption vulnerability

MEDIUM 5.8
PyPI

CVE-2025-52967

MLFlow SSRF via gateway_proxy_handler

HIGH 7.5
PyPI

CVE-2024-8859

MLflow has a Local File Read/Path Traversal in dbfs

MEDIUM 5.4
PyPI

CVE-2025-1473

MLflow Cross-Site Request Forgery (CSRF) vulnerability

CRITICAL 10.0
PyPI

CVE-2023-3765

MLflow Path Traversal vulnerability

LOW 3.8
PyPI

CVE-2025-1474

MLflow has Weak Password Requirements

HIGH 8.8
PyPI

CVE-2023-6753

Path traversal in MLflow

HIGH 7.5
PyPI

CVE-2024-2928

Local File Inclusion in mlflow

HIGH 7.5
PyPI

CVE-2024-3848

MLflow has a Local File Read/Path Traversal bypass

CRITICAL 9.3
PyPI

CVE-2024-3573

mlflow vulnerable to Path Traversal

CRITICAL 9.6
PyPI

CVE-2024-27133

MLFlow Cross-site Scripting vulnerability leads to client-side Remote Code Execution

CRITICAL 10.0
PyPI

CVE-2024-0520

Remote code execution in mlflow

CRITICAL 9.6
PyPI

CVE-2024-27132

Cross-site Scripting in MLFlow

MEDIUM 5.3
PyPI

CVE-2024-6838

MLflow Uncontrolled Resource Consumption vulnerability

HIGH 8.2
PyPI

CVE-2022-0736

Insecure Temporary File in mlflow

CRITICAL 10.0
PyPI

CVE-2023-2356

Relative path traversal in mlflow

HIGH 7.5
PyPI

CVE-2023-6909

MLflow Path Traversal Vulnerability

HIGH 8.8
PyPI

CVE-2023-6940

mlflow Command Injection vulnerability

CRITICAL 9.8
PyPI

CVE-2023-6974

MLflow Server-Side Request Forgery (SSRF)

HIGH 7.5
PyPI

CVE-2023-6977

MLflow Local File Disclosure Vulnerability

HIGH 8.1
PyPI

CVE-2024-1560

mlflow vulnerable to Path Traversal

HIGH 7.5
PyPI

CVE-2024-1594

mlflow vulnerable to Path Traversal

HIGH 7.5
PyPI

CVE-2024-1593

mlflow vulnerable to Path Traversal

HIGH 7.5
PyPI

CVE-2024-1483

mlflow Path Traversal vulnerability

HIGH 7.5
PyPI

CVE-2024-1558

mlflow vulnerable to Path Traversal

HIGH 7.0
PyPI

CVE-2024-27134

MLflow's excessive directory permissions allow local privilege escalation

UNKNOWN
PyPI

GHSA-83fm-w79m-64r5

Remote file access vulnerability in `mlflow server` and `mlflow ui` CLIs

HIGH 8.8
PyPI

CVE-2023-4033

mlflow vulnerable to OS Command Injection

HIGH 8.8
PyPI

CVE-2023-6709

Jinja2 template injection in mlflow

MEDIUM 5.4
PyPI

CVE-2024-3099

Undefined Behavior in mlflow

LOW 3.3
PyPI

CVE-2023-1176

Remote file existence check vulnerability in `mlflow server` and `mlflow ui` CLIs

CRITICAL 9.8
PyPI

CVE-2023-2780

mlflow Path Traversal vulnerability

CRITICAL 10.0
PyPI

CVE-2023-6018

Remote Code Execution due to Full Controled File Write in mlflow

MEDIUM 6.5
PyPI

CVE-2023-6568

Cross-site Scripting (XSS) in MLflow

CRITICAL 9.1
PyPI

CVE-2023-6014

MLflow authentication requirement bypass can allow a user to arbitrarily create an account

HIGH 7.5
PyPI

CVE-2023-30172

mflow vulnerable to directory traversal

CRITICAL 10.0
PyPI

CVE-2023-6015

MLflow allowed arbitrary files to be PUT onto the server

HIGH 7.5
PyPI

CVE-2023-43472

Information exposure in MLflow

CRITICAL 10.0
PyPI

CVE-2023-6831

Path traversal in MLflow

HIGH 8.8
PyPI

CVE-2023-6976

MLflow Path Traversal Vulnerability

CRITICAL 9.8
PyPI

CVE-2023-6975

MLFlow Path Traversal Vulnerability

UNKNOWN
PyPI

CVE-2022-0736

CVE-2022-0736

Ready to move

Start Securing

Free, no credit card | First findings in minutes