Vulnerabilities

Last updated 2 hours ago
Filters
Severity
Critical Severity
CVSS Score Range: 9.0–10.0
Critical severity vulnerabilities (CVSS 9.0–10.0). These represent the highest impact issues.
High Severity
CVSS Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
Medium Severity
CVSS Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
Low Severity
CVSS Score Range: < 4.0
Low severity vulnerabilities (CVSS < 4.0). Hygiene issues that can accumulate but pose lower immediate risk.
Unknown Severity
CVSS Score Range: No score
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
Package Summary Severity Published Modified
mlflow MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding) Critical 9.3 1 month ago 7 hours ago
mlflow MLflow AI Gateway permits SSRF through an unvalidated api_base High Risk 7.1 1 month ago 22 days ago
mlflow MLflow AI Gateway permits SSRF through an unvalidated api_base High Risk 7.1 22 days ago 22 days ago
mlflow mlflow: FastAPI job endpoints under `/ajax-api/3.0/jobs/*` are not protected by authentication or authorization Critical 9.1 6 months ago 22 days ago
mlflow Arbitrary file write via tar traversal in mlflow High Risk 8.1 6 months ago 22 days ago
mlflow MLFlow path traversal vulnerability Critical 9.6 6 months ago 22 days ago
mlflow MLflow has a command injection in mlflow/sagemaker/__init__.py High Risk 7.5 6 months ago 22 days ago
mlflow MLflow Tracking Server Artifact Handler Directory Traversal Remote Code Execution Vulnerability High Risk 8.1 7 months ago 22 days ago
mlflow MLflow is vulnerable to Stored Cross-Site Scripting (XSS) caused by unsafe parsing of YAML-based MLmodel artifacts in its web interface Medium Risk 5.4 5 months ago 22 days ago
mlflow MLflow is vulnerable to an authorization bypass affecting the AJAX endpoint Medium Risk 4.3 5 months ago 22 days ago
mlflow MLflow Command Injection vulnerability Critical 10.0 6 months ago 22 days ago
mlflow MLFlow allows Tracing + Assessments Access High Risk 8.1 6 months ago 22 days ago
mlflow MLflow Use of Default Password Authentication Bypass Vulnerability Critical 9.8 7 months ago 22 days ago
mlflow mlflow Creates of Temporary File in Directory with Insecure Permissions High Risk 7.0 8 months ago 22 days ago
mlflow MLFlow is vulnerable to DNS rebinding attacks due to a lack of Origin header validation High Risk 8.1 8 months ago 22 days ago
mlflow MLFlow unsafe deserialization High Risk 8.8 2 years ago 22 days ago
mlflow MLFlow improper input validation High Risk 8.8 2 years ago 22 days ago
mlflow-ui Malicious code in mlflow-ui (PyPI) Unknown 2 months ago 23 days ago
mlflow MLFLOW_ALLOW_PICKLE_DESERIALIZATION=False safety control bypassed by mlflow.statsmodels flavor — RCE via crafted model artifact High Risk 8.8 1 month ago 1 month ago
mlflow MLFlow Creates a Temporary File With Insecure Permissions High Risk 7.0 4 months ago 1 month ago
mlflow-otel-instrumentor Malicious code in mlflow-otel-instrumentor (PyPI) Unknown 1 month ago 1 month ago
mlflow MLflow: CreateModelVersion source validation does not check READ permission on referenced run_id High Risk 7.1 1 month ago 1 month ago
mlflow MLflow: LogInputs endpoint bypasses per-run UPDATE authorization in basic-auth Medium Risk 6.5 1 month ago 1 month ago
mlflow MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding) Critical 9.3 1 month ago 1 month ago
mlflow MLflow: trace API endpoints lack proper authorization validators High Risk 8.1 3 months ago 1 month ago
mlflow MLflow: trace API endpoints lack proper authorization validators High Risk 8.1 1 month ago 1 month ago
mlflow No summary available Unknown 4 months ago 2 months ago
mlflow MLflow: Deterministic sampling in dataset digest enables predictable collisions Low Risk 3.6 4 months ago 2 months ago
mlflow MLflow allows unauthorized access to multipart upload endpoints when the `--serve-artifacts` mode is enabled Critical 9.0 4 months ago 2 months ago
mlflow No summary available Critical 9.0 4 months ago 2 months ago
mlflow No summary available High Risk 8.6 4 months ago 2 months ago
mlflow No summary available High Risk 7.1 4 months ago 2 months ago
mlflow No summary available High Risk 7.7 4 months ago 2 months ago
mlflow MLflow authenticated users can enumerate any registered model versions due to lack of per-model permissions checks Medium Risk 6.5 4 months ago 2 months ago
mlflow MLflow authenticated users can enumerate any registered model versions due to lack of per-model permissions checks Medium Risk 6.5 2 months ago 2 months ago
mlflow MLFlow Creates a Temporary File With Insecure Permissions High Risk 7.0 2 months ago 2 months ago
mlflow Arbitrary file write via tar traversal in mlflow High Risk 8.1 2 months ago 2 months ago
mlflow MLflow has a command injection in mlflow/sagemaker/__init__.py High Risk 7.5 2 months ago 2 months ago
mlflow MLflow allows an unauthenticated remote attacker to read arbitrary files from the server's filesystem High Risk 7.5 4 months ago 2 months ago
mlflow MLflow allows an unauthenticated remote attacker to read arbitrary files from the server's filesystem High Risk 7.5 2 months ago 2 months ago
mlflow MLflow: Any authenticated user can enumerate all gateway secrets, endpoints, and model definitions Medium Risk 6.5 4 months ago 2 months ago
mlflow MLflow: Any authenticated user can enumerate all gateway secrets, endpoints, and model definitions Medium Risk 6.5 2 months ago 2 months ago
mlflow MLFlow allows Tracing + Assessments Access High Risk 8.1 2 months ago 2 months ago
mlflow MLflow Tracking Server Artifact Handler Directory Traversal Remote Code Execution Vulnerability High Risk 8.1 2 months ago 2 months ago
mlflow Remote Code Execution due to Full Controled File Write in mlflow Critical 10.0 3 months ago 2 months ago
mlflow MLflow Has a Server-Side Request Forgery (SSRF) Vulnerability High Risk 7.1 4 months ago 2 months ago
mlflow MLflow: Environment variable injection in AI Gateway secrets enables server-side credential exfiltration Critical 9.1 4 months ago 2 months ago
mlflow MLflow: unauthenticated access to certain FastAPI routes High Risk 8.6 4 months ago 2 months ago
mlflow mlflow Command Injection vulnerability High Risk 8.8 2 years ago 2 months ago
mlflow mlflow Command Injection vulnerability High Risk 8.8 2 months ago 2 months ago