Launch Week Day 1: Announcing Security Design Review
HIGH 8.8 PyPI

MLFlow improper input validation

GHSA-pqcv-qw2r-r859 · BIT-mlflow-2024-37061 · CVE-2024-37061

Published · Modified

Description

Remote Code Execution can occur in versions of the MLflow platform running version 1.11.0 or newer, enabling a maliciously crafted MLproject to execute arbitrary code on an end user’s system when run due to unfiltered input.

Ready to move

Start Securing

Free, no credit card | First findings in minutes