Launch Week Day 1: Announcing Security Design Review
CRITICAL 9.6 PyPI

Cross-site Scripting in MLFlow

GHSA-6749-m5cp-6cg7 · BIT-mlflow-2024-27132 · CVE-2024-27132 · PYSEC-2024-240

Published · Modified

Description

Insufficient sanitization in MLflow leads to XSS when running an untrusted recipe.

This issue leads to a client-side RCE when running an untrusted recipe in Jupyter Notebook.

The vulnerability stems from lack of sanitization over template variables.

Ready to move

Start Securing

Free, no credit card | First findings in minutes