MLflowGHSA-4x5p-f36r-mxxr
mlflow Creates of Temporary File in Directory with Insecure Permissions
High7.0CVE-2025-10279 · Published Feb 2, 2026 · updated Sep 10, 2026
In mlflow version 2.20.3, the temporary directory used for creating Python virtual environments is assigned insecure world-writable permissions (0o777). This vulnerability allows an attacker with write access to the `/tmp` directory to exploit a race condition and overwrite `.py` files in the virtual environment, leading to arbitrary code execution. The issue is resolved in version 3.4.0.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| mlflow PyPI | < 3.4.0rc0 | 3.4.0rc0 |
Details and references
- CVSS 3.0
- CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-379
- Also known as
- BIT-mlflow-2025-10279, CVE-2025-10279, PYSEC-2026-1639
More MLflow advisories
All MLflow| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Mar 27 | MLFlow allows Tracing + Assessments Access | High8.1 | No fix yet |
| Mar 19 | Arbitrary file write via tar traversal in mlflow | High8.1 | 3.9.0rc0 |
| Mar 16 | MLflow has a command injection in mlflow/sagemaker/__init__.py | High7.5 | 3.8.0rc0 |
| Feb 21 | MLflow Tracking Server Artifact Handler Directory Traversal Remote Code Execution Vulnerability | High8.1 | 3.8.0rc0 |
| Feb 21 | MLflow Use of Default Password Authentication Bypass Vulnerability | Critical9.8 | 3.8.0rc0 |
| Jan 12 | MLFlow is vulnerable to DNS rebinding attacks due to a lack of Origin header validation | High8.1 | 3.5.0 |