Skip to content
MLflowGHSA-4x5p-f36r-mxxr

mlflow Creates of Temporary File in Directory with Insecure Permissions

High7.0CVE-2025-10279 · Published Feb 2, 2026 · updated Sep 10, 2026

In mlflow version 2.20.3, the temporary directory used for creating Python virtual environments is assigned insecure world-writable permissions (0o777). This vulnerability allows an attacker with write access to the `/tmp` directory to exploit a race condition and overwrite `.py` files in the virtual environment, leading to arbitrary code execution. The issue is resolved in version 3.4.0.

GitHub advisory

Affected versions

PackageAffectedFixed in
mlflow
PyPI
< 3.4.0rc03.4.0rc0
Details and references
CVSS 3.0
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-379
Also known as
BIT-mlflow-2025-10279, CVE-2025-10279, PYSEC-2026-1639

More MLflow advisories

All MLflow

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.