Skip to content
MLflowGHSA-969w-gqqr-g6j3

MLflow Cross-Site Request Forgery (CSRF) vulnerability

Medium5.4CVE-2025-1473 · Published Mar 20, 2025 · updated Jul 7, 2026

A Cross-Site Request Forgery (CSRF) vulnerability exists in the Signup feature of mlflow/mlflow versions 2.17.0 to 2.20.1. This vulnerability allows an attacker to create a new account, which may be used to perform unauthorized actions on behalf of the malicious user.

GitHub advisory

Affected versions

PackageAffectedFixed in
mlflow
PyPI
>= 2.17.0, < 2.20.32.20.3
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-352
Also known as
BIT-mlflow-2025-1473, CVE-2025-1473, PYSEC-2026-1646

More MLflow advisories

All MLflow
Advisory
MLFlow SSRF via gateway_proxy_handler
Medium5.8Jun 23, 2025
MLflow has Weak Password Requirements
Low3.8Mar 20, 2025
MLflow Uncontrolled Resource Consumption vulnerability
Medium5.9Mar 20, 2025
MLflow has a Local File Read/Path Traversal in dbfs
High7.5Mar 20, 2025
MLflow Uncontrolled Resource Consumption vulnerability
Medium5.3Mar 20, 2025
MLflow's excessive directory permissions allow local privilege escalation
High7.0Nov 25, 2024

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.