Skip to content
MLflowGHSA-5p3h-7fwh-92rc

Remote Code Execution due to Full Controled File Write in mlflow

Critical10.0CVE-2023-6018 · Published Nov 16, 2023 · updated Jun 29, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
mlflow
PyPI
< 2.9.22.9.2
Details and references

The mlflow web server includes tools for tracking experiments, packaging code into reproducible runs, and sharing and deploying models. As this vulnerability allows to write / overwrite any file on the file system, it gives a lot of ways to archive code execution (like overwriting `/home/<user>/.bashrc`). A malicious user could use this issue to get command execution on the vulnerable machine and get access to data & models information.

CVSS 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-78
Also known as
BIT-mlflow-2023-6018, CVE-2023-6018, PYSEC-2026-417

More MLflow advisories

All MLflow
DateAdvisory
Nov 162023MLflow allowed arbitrary files to be PUT onto the server
CVE-2023-6015Critical10.0fixed in 2.8.1
Nov 162023MLflow authentication requirement bypass can allow a user to arbitrarily create an account
CVE-2023-6014Critical9.1fixed in 2.8.0
Dec 52023Information exposure in MLflow
CVE-2023-43472High7.5fixed in 2.9.0
Dec 72023Cross-site Scripting (XSS) in MLflow
CVE-2023-6568Medium6.5fixed in 2.9.0
Dec 122023Jinja2 template injection in mlflow
CVE-2023-6709High8.8fixed in 2.9.2
Dec 132023Path traversal in MLflow
CVE-2023-6753High8.8fixed in 2.9.2

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.