Skip to content
MLflowGHSA-6749-m5cp-6cg7

Cross-site Scripting in MLFlow

Critical9.6CVE-2024-27132 · Published Feb 24, 2024 · updated Apr 8, 2025

Insufficient sanitization in MLflow leads to XSS when running an untrusted recipe. This issue leads to a client-side RCE when running an untrusted recipe in Jupyter Notebook. The vulnerability stems from lack of sanitization over template variables.

GitHub advisory

Affected versions

PackageAffectedFixed in
mlflow
PyPI
< 2.10.02.10.0
Details and references

More MLflow advisories

All MLflow
Advisory
mlflow vulnerable to Path Traversal
High7.5Apr 16, 2024
mlflow vulnerable to Path Traversal
High7.5Apr 16, 2024
mlflow vulnerable to Path Traversal
High7.5Apr 16, 2024
mlflow vulnerable to Path Traversal
High8.1Apr 16, 2024
mlflow Path Traversal vulnerability
High7.5Apr 16, 2024
MLFlow Cross-site Scripting vulnerability leads to client-side Remote Code Execution
Critical9.6Feb 24, 2024

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.