Vulnerability GHSA-8c7q-86fq-vvmh

Critical
CRITICAL RISK
CVSS Score: 9.0
Score Range: 9.0–10.0
Critical severity vulnerabilities (CVSS 9.0–10.0). These represent the highest impact issues.
4 months ago
May 26, 2026 at 01:30 PM UTC
MLflow allows unauthorized access to multipart upload endpoints when the `--serve-artifacts` mode is enabled
0.0.1 - 3.10.0rc0
0.0.1 - 3.10.0rc0

Summary

MLflow allows unauthorized access to multipart upload endpoints when the `--serve-artifacts` mode is enabled

Details

A vulnerability in MLflow versions <=3.10.1.dev0 allows unauthorized access to multipart upload (MPU) endpoints when the --serve-artifacts mode is enabled. The authorization logic does not enforce resource-level permission checks for /mlflow-artifacts/mpu/* endpoints, enabling attackers to overwrite artifacts belonging to other users. This can lead to unauthorized cross-user writes, model supply chain poisoning, and arbitrary code execution when compromised models are loaded. The issue is resolved in version 3.10.0.

Impacted packages

Timeline

Published
4 months ago
May 26, 2026 at 01:30 PM UTC
Fixed (3.10.0)
7 months ago
February 20, 2026 at 01:48 PM UTC
Last Modified
6 hours ago
October 06, 2026 at 07:00 PM UTC