Skip to content
MLflowGHSA-5r3q-93q3-f978

MLflow Path Traversal Vulnerability

High7.5CVE-2023-6909 · Published Dec 20, 2023 · updated Feb 15, 2025

Path Traversal: '\..\filename' in GitHub repository mlflow/mlflow prior to 2.9.2.

GitHub advisory

Affected versions

PackageAffectedFixed in
mlflow
PyPI
< 2.9.22.9.2
Details and references

More MLflow advisories

All MLflow
Advisory
MLflow Server-Side Request Forgery (SSRF)
Critical9.8Dec 20, 2023
MLFlow Path Traversal Vulnerability
Critical9.8Dec 20, 2023
MLflow Local File Disclosure Vulnerability
High7.5Dec 20, 2023
MLflow Path Traversal Vulnerability
High8.8Dec 20, 2023
mlflow Command Injection vulnerability
High8.8Dec 19, 2023
Path traversal in MLflow
Critical10.0Dec 15, 2023

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.