Skip to content
MLflowGHSA-43c4-9qgj-x742

MLFlow unsafe deserialization

High8.8CVE-2024-37053 · Published Jun 4, 2024 · updated Jul 7, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
mlflow
PyPI
>= 1.1.0, <= 2.14.1No fix yet
Details and references

Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.1.0 or newer, enabling a maliciously uploaded scikit-learn model to run arbitrary code on an end user’s system when interacted with.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-502
Also known as
BIT-mlflow-2024-37053, CVE-2024-37053, PYSEC-2026-1636

More MLflow advisories

All MLflow
DateAdvisory
Jun 42024MLFlow unsafe deserialization
CVE-2024-37052High8.8no fix yet
Jun 42024MLFlow unsafe deserialization
CVE-2024-37056High8.8no fix yet
Jun 42024MLFlow unsafe deserialization
CVE-2024-37054High8.8no fix yet
Jun 42024MLFlow unsafe deserialization
CVE-2024-37055High8.8no fix yet
Jun 42024MLFlow unsafe deserialization
CVE-2024-37060High8.8no fix yet
Jun 42024MLFlow unsafe deserialization
CVE-2024-37058High8.8no fix yet

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.