Skip to content
MLflowGHSA-4rqf-8pfm-p36r

MLflow has a Local File Read/Path Traversal in dbfs

High7.5CVE-2024-8859 · Published Mar 20, 2025 · updated Jul 7, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
mlflow
PyPI
< 2.17.0rc02.17.0rc0
Details and references

A path traversal vulnerability exists in mlflow/mlflow version 2.15.1. When users configure and use the dbfs service, concatenating the URL directly into the file protocol results in an arbitrary file read vulnerability. This issue occurs because only the path part of the URL is checked, while parts such as query and parameters are not handled. The vulnerability is triggered if the user has configured the dbfs service, and during usage, the service is mounted to a local directory.

CVSS 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-22, CWE-29
Also known as
BIT-mlflow-2024-8859, CVE-2024-8859, PYSEC-2026-1638

More MLflow advisories

All MLflow
DateAdvisory
Mar 202025MLflow Uncontrolled Resource Consumption vulnerability
CVE-2024-6838Medium5.3no fix yet
Mar 202025MLflow Uncontrolled Resource Consumption vulnerability
CVE-2025-0453Medium5.9no fix yet
Mar 202025MLflow has Weak Password Requirements
CVE-2025-1474Low3.8fixed in 2.19.0
Mar 202025MLflow Cross-Site Request Forgery (CSRF) vulnerability
CVE-2025-1473Medium5.4fixed in 2.20.3
Jun 232025MLFlow SSRF via gateway_proxy_handler
CVE-2025-52967Medium5.8fixed in 2.22.2, 3.1.0
Nov 252024MLflow's excessive directory permissions allow local privilege escalation
CVE-2024-27134High7.0fixed in 2.16.0

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.